CVE-2025-10881

Summary

A maliciously crafted CATPRODUCT file, when parsed through certain Autodesk products, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

Affected Software

VendorProductVersion RangeStatus
AutodeskShared Components1.8.0 < 1.9.0affected
AutodeskAutoCAD2025.0.0 < 2025.1.4affected
AutodeskAutoCAD2024.0.0 < 2024.1.9affected

Weaknesses

  • CWE-122: CWE-122 Heap-Based Buffer Overflow

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References