CVE-2025-7675

A maliciously crafted 3DM file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:autodesk:shared_components:2026.2:*:*:*:*:*:*:*
OR cpe:2.3:a:autodesk:3ds_max:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:advance_steel:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_architecture:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_electrical:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_map_3d:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_mechanical:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_mep:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_plant_3d:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:civil_3d:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:infraworks:2026:-:*:*:*:*:*:*
cpe:2.3:a:autodesk:inventor:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:revit:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:revit_lt:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:vault:2026:*:*:*:*:*:*:*

History

19 Aug 2025, 14:15

Type Values Removed Values Added
References
  • () https://www.autodesk.com/products/autodesk-access/overview -
CVSS v2 : unknown
v3 : 7.8
v2 : unknown
v3 : unknown

04 Aug 2025, 13:49

Type Values Removed Values Added
CPE cpe:2.3:a:autodesk:autocad:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_mep:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:revit:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:3ds_max:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:inventor:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:advance_steel:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_electrical:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_plant_3d:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_mechanical:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_map_3d:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:vault:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:revit_lt:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:shared_components:2026.2:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_architecture:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:infraworks:2026:-:*:*:*:*:*:*
cpe:2.3:a:autodesk:civil_3d:2026:*:*:*:*:*:*:*
References () https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0015 - () https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0015 - Vendor Advisory
First Time Autodesk autocad Electrical
Autodesk revit Lt
Autodesk autocad Map 3d
Autodesk shared Components
Autodesk autocad
Autodesk autocad Mep
Autodesk civil 3d
Autodesk autocad Mechanical
Autodesk autocad Plant 3d
Autodesk 3ds Max
Autodesk advance Steel
Autodesk autocad Architecture
Autodesk infraworks
Autodesk vault
Autodesk
Autodesk revit
Autodesk inventor

29 Jul 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-29 18:15

Updated : 2025-08-19 14:15


NVD link : CVE-2025-7675

Mitre link : CVE-2025-7675


JSON object : View

Products Affected

autodesk

  • revit
  • autocad_mechanical
  • vault
  • autocad
  • inventor
  • advance_steel
  • autocad_electrical
  • revit_lt
  • autocad_plant_3d
  • shared_components
  • autocad_mep
  • autocad_map_3d
  • civil_3d
  • 3ds_max
  • autocad_architecture
  • infraworks
CWE

No CWE.