Impact
A maliciously crafted IFC file can trigger uncontrolled recursion when parsed by certain Autodesk Shared Components, causing the application to terminate unexpectedly. This results in a denial‑of‑service condition where the affected program is unable to continue processing, potentially impacting business continuity. The weakness identified is uncontrolled recursion (CWE‑674).
Affected Systems
The vulnerability affects Autodesk Shared Components versions 1.11.0.3 and 2.0.4.1, which are used in several Autodesk products and can be present in installations that include these component versions.
Risk and Exploitability
The CVSS base score of 5.5 indicates moderate severity. Based on the description, it is inferred that exploitation requires the victim to open a specially crafted IFC file, so the attack vector is local user action or social engineering. No publicly available exploits are known and the vulnerability is not listed in the CISA KEV catalog, suggesting a lower likelihood of widespread attacks. Nevertheless, a successful exploitation would disrupt the affected application by causing it to crash.
OpenCVE Enrichment