Impact
A maliciously crafted DWG or DXF file, when parsed by Autodesk AutoCAD, can trigger an out-of-bounds read. This vulnerability allows read access to memory beyond the intended buffer, potentially revealing sensitive information or causing the application to crash. The weakness is a classic buffer over-read (CWE‑125).
Affected Systems
Affected products include Autodesk AutoCAD 2027, Autodesk AutoCAD LT 2027, and Autodesk DWG TrueView 2027. No prior version is listed as affected, so any installation of the 2027 editions is considered vulnerable.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate severity. The EPSS score of less than 1% suggests a low probability of real-world exploitation at the time of analysis, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local, based on a user opening a malicious DWG or DXF file. While the vulnerability does not provide remote code execution, it can still lead to denial of service or accidental disclosure of confidential data. Consequently, organizations should treat this as a risk that could impact system availability and confidentiality but is low in exploitation likelihood.
OpenCVE Enrichment