Impact
A maliciously crafted PDF file, when parsed through the Autodesk Revit PDF parser, forces an out‑of‑bounds write that corrupts memory. This flaw can crash the application, corrupt data or enable an attacker to execute arbitrary code in the context of the running process. The underlying weakness is a classic buffer overwrite, classified as CWE‑787.
Affected Systems
Autodesk Revit versions 2024, 2025, 2026, and 2027 are affected. The likely attack vector involves opening or importing PDF files through Revit's default parser, but this is inferred from the description.
Risk and Exploitability
The CVSS score of 7.8 signals a medium‑high risk. An EPSS score of <1% indicates a low but nonzero likelihood of exploitation. The flaw is not listed in the CISA KEV catalog. The likely attack vector involves delivering a specially crafted PDF to a user, possibly via a local file or a network source, which could lead to arbitrary code execution within the application, but this is inferred from the description.
OpenCVE Enrichment