CVE-2026-0874
7.8Autodesk · Shared Components
A malicious CATPART file can trigger an out-of-bounds write in Autodesk Shared Components, potentially leading to arbitrary code execution.
Executive summary
Autodesk Shared Components contains an out-of-bounds write vulnerability that could allow a local attacker to achieve arbitrary code execution via a specially crafted CATPART file.
Vulnerability
This vulnerability is a CWE-787 out-of-bounds write flaw triggered when parsing CATPART files. An unauthenticated attacker can exploit this via a crafted file that requires user interaction to process.
Business impact
Successful exploitation of this vulnerability could lead to total system compromise, including the execution of arbitrary code within the context of the user process. With a CVSS score of 7.8, this represents a high-severity risk that could facilitate unauthorized data access, system crashes, or lateral movement within the environment.
Remediation
Immediate Action: Update Autodesk Shared Components to version 1.10.0.4 or later immediately to resolve the vulnerable code path.
Proactive Monitoring: Monitor system logs for unexpected application crashes or suspicious file access patterns involving CATPART files.
Compensating Controls: Restrict the opening of untrusted CATPART files from external sources and ensure that endpoint detection and response (EDR) tools are configured to monitor for process anomalies.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for arbitrary code execution, this vulnerability poses a significant risk to workstations utilizing Autodesk software. Administrators should prioritize the deployment of the security update provided by Autodesk. Users should exercise caution and avoid opening CATPART files from unverified or suspicious sources until the patch is applied.