Description
A maliciously crafted DWG file, when parsed through certain Autodesk applications, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
Problem types
Product status
2025 (custom) before 2025.1.2
2024 (custom) before 2024.1.7
2023 (custom) before 2023.1.7
2025 (custom) before 2025.1.2
2024 (custom) before 2024.1.7
2023 (custom) before 2023.1.7
2025 (custom) before 2025.1.2
2024 (custom) before 2024.1.7
2023 (custom) before 2023.1.7
2025 (custom) before 2025.1.2
2024 (custom) before 2024.1.7
2023 (custom) before 2023.1.7
2025 (custom) before 2025.1.2
2024 (custom) before 2024.1.7
2023 (custom) before 2023.1.7
2025 (custom) before 2025.1.2
2024 (custom) before 2024.1.7
2023 (custom) before 2023.1.7
2025 (custom) before 2025.1.2
2024 (custom) before 2024.1.7
2023 (custom) before 2023.1.7
2025 (custom) before 2025.1.2
2024 (custom) before 2024.1.7
2023 (custom) before 2023.1.7
2025 (custom) before 2025.1.2
2024 (custom) before 2024.1.7
2023 (custom) before 2023.1.7
2025 (custom) before 2025.1.2
2024 (custom) before 2024.1.7
2025 (custom) before 2025.1.2
2024 (custom) before 2024.1.7
2023 (custom) before 2023.1.7
References
www.autodesk.com/products/autodesk-access/overview
www.autodesk.com/products/dwg-trueview/overview
www.autodesk.com/trust/security-advisories/adsk-sa-2025-0004