Impact
An out‑of‑bounds read in the PDF parsing component of Autodesk AutoCAD, AutoCAD LT, and Revit allows a maliciously crafted PDF file to trigger a crash, leak memory contents, or ultimately execute arbitrary code in the context of the running process. The flaw is classified as CWE‑125, representing a failure to properly validate input bounds during memory access.
Affected Systems
All Autodesk desktop products listed in the CVE—AutoCAD, AutoCAD LT, and Revit—covering 2024 through 2027 releases are affected. The vulnerability applies to the general product lines with these release years, meaning users with any of these versions and both standard and LT editions should consider themselves vulnerable until a corrective update is installed. Specific sub‑versions beyond the listed years are not documented, so any build within the affected ranges is presumed impacted.
Risk and Exploitability
The CVSS base score of 7.8 marks the issue as high severity, while the EPSS score below 1% indicates a low but non‑zero likelihood of exploitation at the current moment. Because the attack vector hinges on opening a malicious PDF, it can be delivered via email attachments, shared network files, or automated import processes, which are typical in design and engineering environments. The absence of a CISA KEV listing does not mitigate the risk; any process that renders PDFs from user input remains a potential entry point. Prompt application of vendor patches and disabling automatic PDF rendering are recommended to mitigate these risks.
OpenCVE Enrichment