Impact
A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Use‑After‑Free vulnerability. The attacker can cause a crash, disclose sensitive data, or execute arbitrary code in the context of the current process. This flaw stems from improper memory management during PDF parsing and is classified as CWE‑416. Those who can supply or deliver a crafted PDF that the affected Autodesk products will open are the primary risk group. The vulnerability can compromise confidentiality, integrity, and availability of the application and the underlying system.
Affected Systems
Autodesk AutoCAD, AutoCAD LT, and Revit releases from 2024 through 2027 are affected. Users of any of these versions on supported platforms may be vulnerable if they open a maliciously crafted PDF file. The vulnerability resides in the core PDF parsing component of these applications.
Risk and Exploitability
The CVSS base score is 7.8, indicating high severity. The EPSS score is <1% (≈0.00141), suggesting a very low baseline exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit it by providing a malicious PDF to any user who opens it; therefore, the likely attack vector is a local or distant document open. Once the attack succeeds, the attacker can gain code execution privileges with the same rights as the affected process, potentially compromising the underlying operating system.
OpenCVE Enrichment