A maliciously crafted DWG file, when parsed through certain Autodesk applications, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
CVSS
No CVSS.
References
Configurations
Configuration 1 (hide)
|
History
19 Aug 2025, 13:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
30 Jul 2025, 17:25
Type | Values Removed | Values Added |
---|---|---|
First Time |
Autodesk autocad Electrical
Autodesk autocad Map 3d Autodesk autocad Autodesk autocad Mep Autodesk civil 3d Autodesk autocad Mechanical Autodesk autocad Plant 3d Autodesk infrastructure Parts Editor Autodesk advance Steel Autodesk dwg Trueview Autodesk autocad Architecture Autodesk autocad Lt Autodesk navisworks Manage Autodesk navisworks Simulate Autodesk vault Autodesk Autodesk revit Autodesk inventor |
|
References | () https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0004 - Vendor Advisory | |
CPE | cpe:2.3:a:autodesk:autocad:*:*:*:*:*:-:*:* cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:inventor:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:revit:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:dwg_trueview:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:infrastructure_parts_editor:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:navisworks_manage:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:navisworks_simulate:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:-:*:* cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:* cpe:2.3:a:autodesk:vault:*:*:*:*:*:*:*:* |
15 Apr 2025, 21:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-04-15 21:15
Updated : 2025-08-19 13:15
NVD link : CVE-2025-1276
Mitre link : CVE-2025-1276
JSON object : View
Products Affected
autodesk
- revit
- autocad_mechanical
- navisworks_manage
- autocad
- inventor
- infrastructure_parts_editor
- autocad_electrical
- advance_steel
- navisworks_simulate
- autocad_plant_3d
- vault
- autocad_mep
- autocad_map_3d
- civil_3d
- dwg_trueview
- autocad_architecture
- autocad_lt
CWE
No CWE.