Autodesk Products Use-After-Free Vulnerability in PRT File Parsing

Vulnerability

A use-after-free vulnerability has been identified in multiple Autodesk products, including AutoCAD 2026 and several specialized toolsets, as well as applications like 3ds Max, Civil 3D, Inventor, Revit, and Vault. This vulnerability arises when a maliciously crafted PRT file is parsed, potentially leading to memory corruption, crashes, unauthorized reading of sensitive data, or execution of arbitrary code within the current process.

Impact

Exploitation of this vulnerability can cause application crashes, unauthorized access to sensitive data, or allow for arbitrary code execution in the context of the current user process.

Remediation

Users are advised to update to Autodesk Shared Components version 2026.3, available through the Autodesk Access or Accounts Portal. No need to update or reinstall individual Autodesk products, as the shared component update can be applied independently.

Added: Jul 29, 2025, 6:24 PM
Updated: Jul 29, 2025, 6:24 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
4.4
remediation
7.7
relevance
0.3
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.