Autodesk Products Out-of-Bounds Write Vulnerability in PDF File Parsing

Vulnerability

A vulnerability allowing out-of-bounds write has been identified in certain Autodesk desktop products, including Autodesk Revit, AutoCAD and its specialized toolsets, Advance Steel, and Civil 3D. This vulnerability arises when a maliciously crafted PDF file is parsed, potentially leading to a crash, data corruption, or arbitrary code execution within the current process.

Impact

Exploitation of this vulnerability can cause a crash, data corruption, or arbitrary code execution in the context of the current process.

Remediation

Users can update to the latest versions that mitigate this vulnerability via Autodesk Access or the Accounts Portal. Specific update versions vary by product.

Added: Sep 16, 2025, 3:34 PM
Updated: Sep 16, 2025, 3:34 PM

Vulnerability Rating

Custom Algorithm
spread
6.6
impact
10.0
exploitability
4.4
remediation
7.7
relevance
0.5
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.