CVE-2026-0874

7.8

Autodesk · Shared Components

A malicious CATPART file can trigger an out-of-bounds write in Autodesk Shared Components, potentially leading to arbitrary code execution.

Executive summary

Autodesk Shared Components contains an out-of-bounds write vulnerability that could allow a local attacker to achieve arbitrary code execution via a specially crafted CATPART file.

Vulnerability

This vulnerability is a CWE-787 out-of-bounds write flaw triggered when parsing CATPART files. An unauthenticated attacker can exploit this via a crafted file that requires user interaction to process.

Business impact

Successful exploitation of this vulnerability could lead to total system compromise, including the execution of arbitrary code within the context of the user process. With a CVSS score of 7.8, this represents a high-severity risk that could facilitate unauthorized data access, system crashes, or lateral movement within the environment.

Remediation

Immediate Action: Update Autodesk Shared Components to version 1.10.0.4 or later immediately to resolve the vulnerable code path.

Proactive Monitoring: Monitor system logs for unexpected application crashes or suspicious file access patterns involving CATPART files.

Compensating Controls: Restrict the opening of untrusted CATPART files from external sources and ensure that endpoint detection and response (EDR) tools are configured to monitor for process anomalies.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for arbitrary code execution, this vulnerability poses a significant risk to workstations utilizing Autodesk software. Administrators should prioritize the deployment of the security update provided by Autodesk. Users should exercise caution and avoid opening CATPART files from unverified or suspicious sources until the patch is applied.

More Autodesk CVEs

Sources