Description
A maliciously crafted IFC file, when parsed through certain Autodesk products, can trigger an Uncontrolled Recursion vulnerability. A malicious actor may leverage this vulnerability to cause the application to terminate unexpectedly, resulting in a denial-of-service. Exploitation requires a user to open a specially crafted IFC file.
Published: 2026-09-02
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A maliciously crafted IFC file can trigger uncontrolled recursion when parsed by certain Autodesk Shared Components, causing the application to terminate unexpectedly. This results in a denial‑of‑service condition where the affected program is unable to continue processing, potentially impacting business continuity. The weakness identified is uncontrolled recursion (CWE‑674).

Affected Systems

The vulnerability affects Autodesk Shared Components versions 1.11.0.3 and 2.0.4.1, which are used in several Autodesk products and can be present in installations that include these component versions.

Risk and Exploitability

The CVSS base score of 5.5 indicates moderate severity. Based on the description, it is inferred that exploitation requires the victim to open a specially crafted IFC file, so the attack vector is local user action or social engineering. No publicly available exploits are known and the vulnerability is not listed in the CISA KEV catalog, suggesting a lower likelihood of widespread attacks. Nevertheless, a successful exploitation would disrupt the affected application by causing it to crash.

Generated by OpenCVE AI on September 3, 2026 at 12:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Autodesk’s latest patch or upgrade Shared Components to a newer version that includes the fix for the uncontrolled recursion issue.
  • Restrict or block the reception of IFC files from untrusted sources, and use file‑type validation to prevent the application from parsing potentially malicious content.
  • Monitor application logs for unexpected crashes or recursion errors and configure alerts to detect denial‑of‑service incidents.

Generated by OpenCVE AI on September 3, 2026 at 12:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description A maliciously crafted IFC file, when parsed through certain Autodesk products, can trigger an Uncontrolled Recursion vulnerability. A malicious actor may leverage this vulnerability to cause the application to terminate unexpectedly, resulting in a denial-of-service. Exploitation requires a user to open a specially crafted IFC file.
Title IFC File Parsing Uncontrolled Recursion in Certain Autodesk Products
First Time appeared Autodesk
Autodesk shared Components
Weaknesses CWE-674
CPEs cpe:2.3:a:autodesk:shared_components:1.11.0.3:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:shared_components:2.0.4.1:*:*:*:*:*:*:*
Vendors & Products Autodesk
Autodesk shared Components
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Autodesk Shared Components
cve-icon MITRE

Status: PUBLISHED

Assigner: autodesk

Published:

Updated: 2026-09-02T14:37:05.500Z

Reserved: 2026-06-30T14:44:00.497Z

Link: CVE-2026-14255

cve-icon Vulnrichment

Updated: 2026-09-02T14:36:57.565Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-02T15:17:37.403

Modified: 2026-09-03T16:44:01.873

Link: CVE-2026-14255

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T13:00:04Z

Weaknesses