Description
A maliciously crafted TIF file, when parsed through certain Autodesk products during image import, can cause an Out-of-Bounds Read in the image handling library. A malicious actor can leverage this vulnerability to cause a denial of service
Published: 2026-08-06
Score: 5.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows a maliciously crafted TIF file to trigger an out‑of‑bounds read in the image handling library used by certain Autodesk applications. When the file is imported, the library reads beyond its memory bounds, which can cause the application to crash. The flaw is classified as CWE‑125 and does not provide code execution or data disclosure. The immediate result is a denial of service to the user of the affected product.

Affected Systems

Autodesk AutoCAD 2027, AutoCAD LT 2027, Revit 2024, Revit 2026, Revit 2027

Risk and Exploitability

The CVSS score of 5.5 indicates a moderate risk level with an unknown likelihood of exploitation due to the lack of an EPSS score. The vulnerability is not listed in CISA KEV and no exploit has been reported publicly. The attack can be carried out by an attacker who has the ability to supply a TIF file to a user or system, such as through email attachments or shared network locations. If the file is opened, the application will terminate, causing a denial of service for that user or the entire system if the crash affects shared services.

Generated by OpenCVE AI on August 7, 2026 at 01:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest patch or update for AutoCAD, AutoCAD LT, and Revit as released by Autodesk in its security advisory.
  • Disallow or control the parsing of TIF files from untrusted sources by restricting import permissions or using application settings to block TIF formats when possible.
  • Apply general file‑content validation policies that restrict processing of oversized or malformed image files and monitor application stability after the update.

Generated by OpenCVE AI on August 7, 2026 at 01:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Description A maliciously crafted TIF file, when parsed through certain Autodesk products during image import, can cause an Out-of-Bounds Read in the image handling library. A malicious actor can leverage this vulnerability to cause a denial of service
Title TIF File Parsing Out-of-Bounds Read in certain Autodesk products
First Time appeared Autodesk
Autodesk autocad
Autodesk autocad Lt
Autodesk revit
Weaknesses CWE-125
CPEs cpe:2.3:a:autodesk:autocad:2027:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_lt:2027:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:revit:2024:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:revit:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:revit:2027:*:*:*:*:*:*:*
Vendors & Products Autodesk
Autodesk autocad
Autodesk autocad Lt
Autodesk revit
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}


Subscriptions

Autodesk Autocad Autocad Lt Revit
cve-icon MITRE

Status: PUBLISHED

Assigner: autodesk

Published:

Updated: 2026-08-06T17:13:10.582Z

Reserved: 2026-04-29T13:03:48.953Z

Link: CVE-2026-7405

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T03:30:06Z

Weaknesses