Impact
A maliciously crafted BMP file can be parsed by certain Autodesk products, forcing an untrusted pointer dereference. This flaw enables execution of code with the privileges of the currently running process, potentially compromising confidentiality, integrity, and availability of the affected system.
Affected Systems
The vulnerability affects Autodesk AutoCAD 2027, AutoCAD LT 2027 and Autodesk Revit versions 2024, 2026, and 2027. Any user running these products who opens or imports a BMP file could be impacted.
Risk and Exploitability
The CVSS score of 7.8 classifies the flaw as high severity, and the EPSS score is not available, indicating a lack of publicly known exploit data. The flaw is not listed in the CISA KEV catalog. Exploitation requires a malicious BMP file to be processed by the software; therefore the attack vector is most likely local or user‑initiated file import, potentially via shared drives or networked file repositories. Once the file is parsed, the attacker can execute arbitrary code in the context of the current process, leading to full system compromise if elevated privileges are present.
OpenCVE Enrichment