Impact
A maliciously crafted PDF file, when processed through Autodesk Revit, triggers an out‑of‑bounds write that can corrupt memory. An attacker exploiting this flaw can cause the application to crash, corrupt data, or potentially execute arbitrary code in the context of the running process. The weakness is a classic buffer overwrite, classified as CWE‑787.
Affected Systems
Revit editions 2026 and 2027 from Autodesk are affected. The vulnerability applies to any instance of the product that uses the default PDF parser when opening or importing PDF files.
Risk and Exploitability
With a CVSS score of 7.8, the flaw presents a medium‑high risk profile. No EPSS value is published, so the current propensity for exploitation is unclear, and the vulnerability does not appear in the CISA KEV catalog. The exploit is likely local or arises when a user opens a malicious PDF, either from a local file or a network location, making it possible for an attacker to trigger the memory corruption simply by supplying a specially crafted PDF to an affected environment.
OpenCVE Enrichment