Description
A maliciously crafted input, when processed by the Autodesk Installer IPC frame parser, may trigger improper validation of an input-specified position or offset, resulting in an out-of-range substring operation. A malicious actor may leverage this vulnerability to cause the NT AUTHORITY\SYSTEM service to terminate unexpectedly, resulting in a denial-of-service condition.
Published: 2026-08-12
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Autodesk Installer IPC frame parser fails to validate an input‑specified position or offset, allowing a maliciously crafted input to trigger an out‑of‑range substring operation. This flaw can cause the NT AUTHORITY\\SYSTEM service to terminate unexpectedly, resulting in a denial‑of‑service condition. The weakness is a bounds‑checking error (CWE‑1285) that compromises service availability.

Affected Systems

Autodesk Installer version 2.22.0 is affected. No other product or version information is provided.

Risk and Exploitability

The vulnerability carries a CVSS score of 5.5, indicating a moderate severity DoS risk. EPSS is unavailable, so the likelihood of exploitation is unknown but not considered negligible. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is inferred to involve manipulating the installer’s IPC channel, potentially requiring local or remote delivery of crafted input. If exploited, the system would experience an abrupt termination of a SYSTEM‑level service, disrupting operational continuity.

Generated by OpenCVE AI on August 13, 2026 at 00:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the latest Autodesk Installer from Autodesk’s official website to address the IPC frame parser flaw.
  • Run the installer with the lowest privilege level possible and restrict IPC channel access to trusted processes.
  • Configure monitoring or recovery options for critical services, and set alerts for unexpected termination of the NT AUTHORITY\\SYSTEM service.

Generated by OpenCVE AI on August 13, 2026 at 00:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
Description A maliciously crafted input, when processed by the Autodesk Installer IPC frame parser, may trigger improper validation of an input-specified position or offset, resulting in an out-of-range substring operation. A malicious actor may leverage this vulnerability to cause the NT AUTHORITY\SYSTEM service to terminate unexpectedly, resulting in a denial-of-service condition.
Title Denial of Service in Autodesk Installer IPC Channel
First Time appeared Autodesk
Autodesk installer
Weaknesses CWE-1285
CPEs cpe:2.3:a:autodesk:installer:2.22.0:*:*:*:*:*:*:*
Vendors & Products Autodesk
Autodesk installer
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Autodesk Installer
cve-icon MITRE

Status: PUBLISHED

Assigner: autodesk

Published:

Updated: 2026-08-12T15:39:45.919Z

Reserved: 2026-07-02T15:55:59.727Z

Link: CVE-2026-14479

cve-icon Vulnrichment

Updated: 2026-08-12T15:39:43.162Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-12T15:17:31.830

Modified: 2026-08-26T16:46:22.330

Link: CVE-2026-14479

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T00:30:06Z

Weaknesses
  • CWE-1285

    Improper Validation of Specified Index, Position, or Offset in Input