Impact
A maliciously crafted DXF file causes the AutoCAD parser to overflow a heap buffer, leading to a crash, data leakage, or execution of arbitrary code in the context of the current process. This qualifies as a Heap‑Based Buffer Overflow (CWE‑122).
Affected Systems
The vulnerability impacts Autodesk AutoCAD, AutoCAD LT, and DWG TrueView. While explicit version numbers are not listed, the CPE entries reference version 2027, suggesting those releases are affected.
Risk and Exploitability
The CVSS score of 7.8 reflects high severity. The EPSS score of less than 1% indicates that the likelihood of exploitation is low, and the vulnerability is not currently listed in the CISA KEV catalog. The likely attack vector requires a malicious DXF file to be opened locally by a user, so the risk is confined to environments allowing end‑users to import arbitrary files. Without an active patch, a successful exploitation would allow code execution with the privileges of the AutoCAD session.
OpenCVE Enrichment