Description
A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
Published: 2026-08-06
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A maliciously crafted BMP file can be parsed by certain Autodesk products, forcing an untrusted pointer dereference. This flaw enables execution of code with the privileges of the currently running process, potentially compromising confidentiality, integrity, and availability of the affected system.

Affected Systems

The vulnerability affects Autodesk AutoCAD 2027, AutoCAD LT 2027 and Autodesk Revit versions 2024, 2026, and 2027. Any user running these products who opens or imports a BMP file could be impacted.

Risk and Exploitability

The CVSS score of 7.8 classifies the flaw as high severity, and the EPSS score is not available, indicating a lack of publicly known exploit data. The flaw is not listed in the CISA KEV catalog. Exploitation requires a malicious BMP file to be processed by the software; therefore the attack vector is most likely local or user‑initiated file import, potentially via shared drives or networked file repositories. Once the file is parsed, the attacker can execute arbitrary code in the context of the current process, leading to full system compromise if elevated privileges are present.

Generated by OpenCVE AI on August 7, 2026 at 01:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Autodesk security patch for AutoCAD, AutoCAD LT and Revit as detailed in the advisory linked in the input.
  • If the patch is not yet available, block or disable BMP file handling on the affected machines by restricting file type permissions or using group policy to prevent import of BMP files.
  • Continuously monitor the Autodesk website and security advisories for further updates and apply them as soon as they become available.

Generated by OpenCVE AI on August 7, 2026 at 01:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Description A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
Title BMP File Parsing Untrusted Pointer Dereference in certain Autodesk products
First Time appeared Autodesk
Autodesk autocad
Autodesk autocad Lt
Autodesk revit
Weaknesses CWE-822
CPEs cpe:2.3:a:autodesk:autocad:2027:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_lt:2027:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:revit:2024:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:revit:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:revit:2027:*:*:*:*:*:*:*
Vendors & Products Autodesk
Autodesk autocad
Autodesk autocad Lt
Autodesk revit
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Autodesk Autocad Autocad Lt Revit
cve-icon MITRE

Status: PUBLISHED

Assigner: autodesk

Published:

Updated: 2026-08-06T17:14:14.165Z

Reserved: 2026-04-29T13:03:51.562Z

Link: CVE-2026-7406

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T06:45:02Z

Weaknesses
  • CWE-822

    Untrusted Pointer Dereference