Description
A maliciously crafted CATPRODUCT file, when parsed through certain Autodesk products, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
Problem types
CWE-122 Heap-Based Buffer Overflow
Product status
2026.0 (custom) before 2026.5
References
www.autodesk.com/products/autodesk-access/overview
www.autodesk.com/trust/security-advisories/adsk-sa-2025-0024
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.