Impact
The vulnerability allows a maliciously crafted TIF file to trigger an out‑of‑bounds read in the image handling library used by certain Autodesk applications. When the file is imported, the library reads beyond its memory bounds, which can cause the application to crash. The flaw is classified as CWE‑125 and does not provide code execution or data disclosure. The immediate result is a denial of service to the user of the affected product.
Affected Systems
Autodesk AutoCAD 2027, AutoCAD LT 2027, Revit 2024, Revit 2026, Revit 2027
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate risk level with an unknown likelihood of exploitation due to the lack of an EPSS score. The vulnerability is not listed in CISA KEV and no exploit has been reported publicly. The attack can be carried out by an attacker who has the ability to supply a TIF file to a user or system, such as through email attachments or shared network locations. If the file is opened, the application will terminate, causing a denial of service for that user or the entire system if the crash affects shared services.
OpenCVE Enrichment