CVE-2025-9460

7.8

Autodesk · Shared Components

A maliciously crafted SLDPRT file parsed by Autodesk Shared Components can trigger an Out-of-Bounds Read, potentially leading to arbitrary code execution.

Executive summary

Autodesk Shared Components contain an Out-of-Bounds Read vulnerability that could allow a remote attacker to execute arbitrary code or access sensitive data through a crafted SLDPRT file.

Vulnerability

This vulnerability is an Out-of-Bounds Read (CWE-125) occurring when the application processes a malformed SLDPRT file. The flaw can be triggered by an unauthenticated user, provided they can induce a victim to open a malicious file within the affected product.

Business impact

The vulnerability carries a CVSS score of 7.8, reflecting its potential for total loss of confidentiality, integrity, and availability. Successful exploitation allows an attacker to execute arbitrary code in the context of the current user, which could result in full system compromise, data exfiltration, or the installation of persistent malicious software.

Remediation

Immediate Action: Update Autodesk Shared Components to version 1.9.0.7 or later as specified in the official vendor advisory (ADSK-SA-2025-0024).

Proactive Monitoring: Monitor system logs for unexpected application crashes or unauthorized process execution originating from file-parsing components.

Compensating Controls: Implement strict email filtering and endpoint protection policies to block or scan suspicious SLDPRT files before they are processed by end-user workstations.

Exploitation status

Public Exploit Available: False

Analyst recommendation

Given the potential for remote code execution, this vulnerability poses a high risk to organizational security. Administrators must prioritize updating all instances of the affected Autodesk Shared Components to the patched version to prevent potential exploitation. If patching is not immediately feasible, restrict the ability of users to open untrusted SLDPRT files.

More Autodesk CVEs

Sources