Description
A maliciously crafted binary file, when present while loading files in certain Autodesk applications, could lead to execution of arbitrary code in the context of the current process due to an untrusted search path being utilized.
Scores
CVSS v3
7.8
EPSS
0.0006
EPSS Percentile
18.8%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-426
Status
published
Products (6)
autodesk/infrastructure_parts_editor
2026 - 2026.0.2
autodesk/inventor
2026 - 2026.0.2
autodesk/navisworks_manage
2026 - 2026.0.2
autodesk/navisworks_simulate
2026 - 2026.0.2
autodesk/revit
2026 - 2026.0.2
autodesk/vault
2026 - 2026.0.2
Published
Jul 24, 2025
Tracked Since
Feb 18, 2026