CVE-2025-5039

A maliciously crafted binary file, when present while loading files in certain Autodesk applications, could lead to execution of arbitrary code in the context of the current process due to an untrusted search path being utilized.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:autodesk:infrastructure_parts_editor:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:inventor:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:navisworks_manage:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:navisworks_simulate:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:revit:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:vault:*:*:*:*:*:*:*:*

History

19 Aug 2025, 14:15

Type Values Removed Values Added
References
  • () https://www.autodesk.com/products/autodesk-access/overview -
CVSS v2 : unknown
v3 : 7.8
v2 : unknown
v3 : unknown

30 Jul 2025, 17:45

Type Values Removed Values Added
First Time Autodesk navisworks Manage
Autodesk infrastructure Parts Editor
Autodesk navisworks Simulate
Autodesk vault
Autodesk
Autodesk revit
Autodesk inventor
CPE cpe:2.3:a:autodesk:navisworks_simulate:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:vault:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:inventor:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:infrastructure_parts_editor:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:navisworks_manage:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:revit:*:*:*:*:*:*:*:*
References () https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0014 - () https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0014 - Vendor Advisory

24 Jul 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-24 17:15

Updated : 2025-08-19 14:15


NVD link : CVE-2025-5039

Mitre link : CVE-2025-5039


JSON object : View

Products Affected

autodesk

  • revit
  • navisworks_simulate
  • navisworks_manage
  • inventor
  • vault
  • infrastructure_parts_editor
CWE

No CWE.