Description
A maliciously crafted RFA file, when parsed through Autodesk Revit, can force a Type Confusion vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
Problem types
Product status
2026 (custom) before 2026.3
2024 (custom) before 2024.3.4
2026 (custom) before 2026.3
2024 (custom) before 2024.3.4
References
www.autodesk.com/products/autodesk-access/overview
www.autodesk.com/trust/security-advisories/adsk-sa-2025-0021