Autodesk Products Heap-Based Overflow Vulnerability via Malicious PDF Parsing

Vulnerability

A heap-based overflow vulnerability has been identified in certain Autodesk products, including Autodesk Revit, AutoCAD and its specialized toolsets, Advance Steel, and Civil 3D. This vulnerability arises when a maliciously crafted PDF file is parsed by the affected software, potentially leading to a crash, unauthorized reading of sensitive data, or execution of arbitrary code within the current process context.

Impact

Exploitation of this vulnerability can cause application crashes, unauthorized access to sensitive data, or allow for the execution of arbitrary code in the context of the user process.

Remediation

Users can update to the latest versions that mitigate this vulnerability through Autodesk Access or the Accounts Portal. Specific update versions vary by product.

Added: Sep 16, 2025, 3:32 PM
Updated: Sep 16, 2025, 3:32 PM

Vulnerability Rating

Custom Algorithm
spread
6.6
impact
10.0
exploitability
4.4
remediation
7.7
relevance
0.5
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.