CVE-2025-1430
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD
Description
A maliciously crafted SLDPRT file, when parsed through Autodesk AutoCAD, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
Affected (36)
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 2022 to 2022.1.6 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| From 2022 to 2022.1.6 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| From 2022 to 2022.1.6 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| From 2022 to 2022.1.6 |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| From 2022 to 2022.1.6 |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| From 2022 to 2022.1.6 |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| From 2022 to 2022.1.6 |
Related CWEs
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.
CWE-787
Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
References (3)
Source: psirt@autodesk.com
Source: psirt@autodesk.com
Source: psirt@autodesk.com
Vendor Advisory
Timeline
No history available yet.