Impact
Malicious PDF files trigger an out‑of‑bounds read inside Autodesk Revit when the file is parsed, allowing an attacker to cause a crash, leak sensitive data, or execute arbitrary code in the current process context. The weakness is described by CWE‑125 and represents an untrusted input validation flaw that can be abused by supplying a deliberately crafted PDF that reads past the bounds of a buffer during parsing.
Affected Systems
Autodesk Revit products, specifically the 2026 and 2027 releases, are affected. Users of these versions who open externally sourced PDF documents may be exposed to the exploit. No specific sub‑version fixes are listed, so all builds under those release lines should be considered vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 7.8 classifies the vulnerability as high severity. EPSS data is not available, but the lack of a public KEV listing does not diminish the potential risk, especially in environments where PDFs are routinely processed or integrated. The attack likely requires the victim to open a malicious PDF or otherwise trigger the parsing routine, which could be delivered via email attachments, shared network drives, or automated import processes. Because the flaw can lead to arbitrary code execution, prompt remediation is advised.
OpenCVE Enrichment