Impact
A maliciously crafted DWG or DXF file can trigger an out-of-bounds read when processed by Autodesk AutoCAD, AutoCAD LT, or DWG TrueView. The flaw, identified as CWE‑125, allows the attacker to cause a crash or potentially read data from process memory during parsing, but it does not lead to code execution or privilege escalation.
Affected Systems
Autodesk AutoCAD 2027, AutoCAD LT 2027, and DWG TrueView 2027 are vulnerable. Any installation of these releases that accepts DWG or DXF files is affected, regardless of the operating system.
Risk and Exploitability
The CVSS score of 5.5 signals a moderate severity. Because the exploit requires a user to open a specially crafted file locally, the attack vector is local and the EPSS score of less than 1 % indicates a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The risk is limited to possible application crashes or accidental disclosure of in‑memory data, without providing remote code execution.
OpenCVE Enrichment