CVE-2026-0875

7.8

Autodesk · Shared Components

A maliciously crafted MODEL file can trigger an Out-of-Bounds Write vulnerability in Autodesk Shared Components, potentially allowing arbitrary code execution.

Executive summary

Autodesk Shared Components contains an out-of-bounds write vulnerability that could allow an attacker to execute arbitrary code or corrupt data through a specially crafted MODEL file.

Vulnerability

The software fails to properly validate MODEL file inputs, leading to a CWE-787 out-of-bounds write condition. An attacker can trigger this flaw by providing a malicious file to a user, requiring local interaction to execute code in the context of the current process.

Business impact

The potential for arbitrary code execution poses a severe risk to organizational assets, as it could allow an attacker to gain control over local workstations or sensitive design files. With a CVSS score of 7.8, this high-severity vulnerability must be addressed to prevent data compromise or significant operational disruption within engineering and design environments.

Remediation

Immediate Action: Update Autodesk Shared Components to version 1.10.0.4 or later by following the instructions provided in the official Autodesk security advisory.

Proactive Monitoring: Monitor workstations for unexpected crashes or abnormal behavior in Autodesk applications, which may indicate an exploitation attempt.

Compensating Controls: Implement file integrity monitoring and restrict the execution of untrusted MODEL files from unknown or external sources.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the high impact of arbitrary code execution, administrators should prioritize patching all systems utilizing the affected Autodesk Shared Components. Ensure that all users are aware of the risks associated with opening MODEL files from unverified sources while the update deployment is finalized.

More Autodesk CVEs

Sources