CVE-2025-5039

HIGH

Autodesk < - Code Injection

Title source: llm
STIX 2.1

Description

A maliciously crafted binary file, when present while loading files in certain Autodesk applications, could lead to execution of arbitrary code in the context of the current process due to an untrusted search path being utilized.

Scores

CVSS v3 7.8
EPSS 0.0006
EPSS Percentile 18.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-426
Status published
Products (6)
autodesk/infrastructure_parts_editor 2026 - 2026.0.2
autodesk/inventor 2026 - 2026.0.2
autodesk/navisworks_manage 2026 - 2026.0.2
autodesk/navisworks_simulate 2026 - 2026.0.2
autodesk/revit 2026 - 2026.0.2
autodesk/vault 2026 - 2026.0.2
Published Jul 24, 2025
Tracked Since Feb 18, 2026