Home
HIGH: 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HDefault status
unaffected
1.6.2.11 (custom) before 1.7.0.10
affected
Default status
unaffected
2025 (custom) before 2025.1.3
affected
2024 (custom) before 2024.1.8
affected
2023 (custom) before 2023.1.8
affected
Description
A maliciously crafted 3DM file, when linked or imported into certain Autodesk products, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
Problem types
CWE-122 Heap-Based Buffer Overflow
Product status
1.6.2.11 (custom) before 1.7.0.10
2025 (custom) before 2025.1.3
2024 (custom) before 2024.1.8
2023 (custom) before 2023.1.8
References
www.autodesk.com/products/autodesk-access/overview
www.autodesk.com/trust/security-advisories/adsk-sa-2025-0015