A maliciously crafted JPG file, when linked or imported into certain Autodesk applications, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
|
Configuration 6 (hide)
|
Configuration 7 (hide)
|
Configuration 8 (hide)
|
Configuration 9 (hide)
|
Configuration 10 (hide)
|
Configuration 11 (hide)
|
Configuration 12 (hide)
|
History
19 Aug 2025, 13:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
08 May 2025, 15:44
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0006 - Vendor Advisory | |
First Time |
Autodesk autocad Electrical
Autodesk advance Steel Autodesk dwg Trueview Autodesk autocad Mechanical Autodesk autocad Architecture Autodesk autocad Map 3d Autodesk autocad Lt Autodesk autocad Autodesk autocad Mep Autodesk civil 3d Autodesk Autodesk revit Autodesk autocad Plant 3d |
|
CPE | cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:dwg_trueview:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:revit:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:* |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
CWE | CWE-787 |
15 Apr 2025, 21:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-04-15 21:15
Updated : 2025-08-19 13:15
NVD link : CVE-2025-1275
Mitre link : CVE-2025-1275
JSON object : View
Products Affected
autodesk
- revit
- autocad_mechanical
- autocad_architecture
- autocad
- autocad_electrical
- autocad_plant_3d
- autocad_mep
- civil_3d
- autocad_map_3d
- dwg_trueview
- advance_steel
- autocad_lt
CWE
CWE-787
Out-of-bounds Write