Ad

CVE-2025-9458

HIGH CVSS 3.1: 7.8 EPSS 0.02%
Updated Nov 19, 2025
Autodesk
Parameter Value
CVSS 7.8 (HIGH)
Type CWE-120 (Buffer Copy without Checking Size), CWE-787 (Out-of-bounds Write)
Vendor Autodesk
Public PoC No

A maliciously crafted PRT file, when parsed through certain Autodesk products, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

Attack Parameters

Attack Vector
Local
Requires local access
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
Required
User action required

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
High
Complete denial of service

CVSS Vector v3.1

Vulnerable Products 16

autodesk:autocad autodesk:shared_components autodesk:autocad_mechanical autodesk:3ds_max autodesk:revit_lt autodesk:autocad_map_3d autodesk:autocad_architecture autodesk:revit autodesk:civil_3d autodesk:autocad_electrical autodesk:autocad_mep autodesk:autocad_plant_3d autodesk:infraworks autodesk:advance_steel autodesk:vault autodesk:inventor

Known Affected Software Configurations 16

Configuration From (including) Up to (excluding)
Autodesk Shared_Components
cpe:2.3:a:autodesk:shared_components:2026.3:*:*:*:*:*:*:*
Autodesk 3ds_Max
cpe:2.3:a:autodesk:3ds_max:2026:*:*:*:*:*:*:*
Autodesk Advance_Steel
cpe:2.3:a:autodesk:advance_steel:2026:*:*:*:*:*:*:*
Autodesk Autocad
cpe:2.3:a:autodesk:autocad:2026:*:*:*:*:*:*:*
Autodesk Autocad_Architecture
cpe:2.3:a:autodesk:autocad_architecture:2026:*:*:*:*:*:*:*
Autodesk Autocad_Electrical
cpe:2.3:a:autodesk:autocad_electrical:2026:*:*:*:*:*:*:*
Autodesk Autocad_Map_3d
cpe:2.3:a:autodesk:autocad_map_3d:2026:*:*:*:*:*:*:*
Autodesk Autocad_Mechanical
cpe:2.3:a:autodesk:autocad_mechanical:2026:*:*:*:*:*:*:*
Autodesk Autocad_Mep
cpe:2.3:a:autodesk:autocad_mep:2026:*:*:*:*:*:*:*
Autodesk Autocad_Plant_3d
cpe:2.3:a:autodesk:autocad_plant_3d:2026:*:*:*:*:*:*:*
Autodesk Civil_3d
cpe:2.3:a:autodesk:civil_3d:2026:*:*:*:*:*:*:*
Autodesk Infraworks
cpe:2.3:a:autodesk:infraworks:2026:-:*:*:*:*:*:*
Autodesk Inventor
cpe:2.3:a:autodesk:inventor:2026:*:*:*:*:*:*:*
Autodesk Revit
cpe:2.3:a:autodesk:revit:2026:*:*:*:*:*:*:*
Autodesk Revit_Lt
cpe:2.3:a:autodesk:revit_lt:2026:*:*:*:*:*:*:*
Autodesk Vault
cpe:2.3:a:autodesk:vault:2026:*:*:*:*:*:*:*