Impact
A malicious PDF can trigger a use‑after‑free bug in Autodesk Revit, potentially allowing the attacker to crash the application, leak data, or run code in the Revit process. The vulnerability stems from improper memory management when parsing PDF files and is classified as CWE‑416. Those who can supply or deliver a crafted PDF that Revit will open are the primary risk groups. This flaw can cause significant compromise of confidentiality, integrity, and availability for users and the system running Revit.
Affected Systems
Autodesk Revit versions 2026 and 2027 are affected. Users running these versions on any supported platform may be vulnerable if they open an attacker‑crafted PDF file. The vulnerability is present the core PDF parsing component of Revit.
Risk and Exploitability
The CVSS base score is 7.8, indicating high severity. EPSS is not available, so the current exploit probability is unknown, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit it by providing a malicious PDF to any user who opens it; therefore, the likely attack vector is a local or distant document open. Once the attack succeeds, the attacker can gain code execution privileges with the same rights as the Revit process, potentially compromising the underlying operating system.
OpenCVE Enrichment