Description
A maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash or disclose sensitive information.
Published: 2026-07-29
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A maliciously crafted DWG or DXF file can trigger an out-of-bounds read when processed by Autodesk AutoCAD, AutoCAD LT, or DWG TrueView. The flaw, identified as CWE‑125, allows the attacker to cause a crash or potentially read data from process memory during parsing, but it does not lead to code execution or privilege escalation.

Affected Systems

Autodesk AutoCAD 2027, AutoCAD LT 2027, and DWG TrueView 2027 are vulnerable. Any installation of these releases that accepts DWG or DXF files is affected, regardless of the operating system.

Risk and Exploitability

The CVSS score of 5.5 signals a moderate severity. Because the exploit requires a user to open a specially crafted file locally, the attack vector is local and the EPSS score of less than 1 % indicates a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The risk is limited to possible application crashes or accidental disclosure of in‑memory data, without providing remote code execution.

Generated by OpenCVE AI on August 2, 2026 at 07:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update AutoCAD, AutoCAD LT, and DWG TrueView to the latest Autodesk release that contains the out‑of‑bounds read fix.
  • Restrict or disable the ability of untrusted users to open DWG or DXF files with AutoCAD by enforcing strict file‑association policies or by removing the application from the system path.
  • Enable endpoint detection or file‑integrity monitoring so that crashes or anomalous memory accesses during DWG/DXF opening trigger alerts for immediate investigation.

Generated by OpenCVE AI on August 2, 2026 at 07:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Autodesk advance Steel
Autodesk autocad Architecture
Autodesk autocad Electrical
Autodesk autocad Map 3d
Autodesk autocad Mechanical
Autodesk autocad Mep
Autodesk autocad Plant 3d
Autodesk civil 3d
CPEs cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:advance_steel:2027:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_architecture:2027:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_electrical:2027:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_lt:2027:*:*:*:*:-:*:*
cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_map_3d:2027:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_mechanical:2027:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_mep:2027:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_plant_3d:2027:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:civil_3d:2027:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:dwg_trueview:*:*:*:*:*:*:*:*
Vendors & Products Autodesk advance Steel
Autodesk autocad Architecture
Autodesk autocad Electrical
Autodesk autocad Map 3d
Autodesk autocad Mechanical
Autodesk autocad Mep
Autodesk autocad Plant 3d
Autodesk civil 3d

Fri, 07 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:autodesk:autocad:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_lt:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:dwg_trueview:2026:*:*:*:*:*:*:*

Wed, 29 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 29 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Description A maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash or disclose sensitive information.
Title DWG or DXF File Parsing Out-of-Bounds Read in Autodesk AutoCAD
First Time appeared Autodesk
Autodesk autocad
Autodesk autocad Lt
Autodesk dwg Trueview
Weaknesses CWE-125
CPEs cpe:2.3:a:autodesk:autocad:2027:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_lt:2027:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:dwg_trueview:2027:*:*:*:*:*:*:*
Vendors & Products Autodesk
Autodesk autocad
Autodesk autocad Lt
Autodesk dwg Trueview
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}


Subscriptions

Autodesk Advance Steel Autocad Autocad Architecture Autocad Electrical Autocad Lt Autocad Map 3d Autocad Mechanical Autocad Mep Autocad Plant 3d Civil 3d Dwg Trueview
cve-icon MITRE

Status: PUBLISHED

Assigner: autodesk

Published:

Updated: 2026-08-07T18:29:35.690Z

Reserved: 2026-07-27T12:14:33.962Z

Link: CVE-2026-17550

cve-icon Vulnrichment

Updated: 2026-07-29T17:57:14.515Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-29T16:17:51.180

Modified: 2026-08-17T14:11:42.100

Link: CVE-2026-17550

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T08:00:04Z

Weaknesses