← Back

CVE-2026-7406

nvd nist
Published: Aug 6, 2026Modified: Sep 4, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: psirt@autodesk.com (Secondary)

Description

A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

Affected (14)

12 products
Advance Steel
Autocad
Autocad Architecture
Autocad Electrical
Autocad Lt
Autocad Map 3d
Autocad Mechanical
Autocad Mep
Autocad Plant 3d
Civil 3d
Dwg Trueview
Revit
Configuration A
14 vulnerable
Vulnerable SoftwareAffected Versions
From 2027 to 2027.1
From 2027 to 2027.1
From 2027 to 2027.1
From 2027 to 2027.1
From 2027 to 2027.1
From 2027 to 2027.1
From 2027 to 2027.1
From 2027 to 2027.1
From 2027 to 2027.1
From 2027 to 2027.1
From 2027 to 2027.1
Autodesk
From 2025 to 2025.3.5
From 2026 to 2026.5
From 2027 to 2027.1

References (2)

Timeline

No history available yet.