CVE-2025-10898

Summary

AA maliciously crafted MODEL file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.

Affected Software

VendorProductVersion RangeStatus
AutodeskShared Components1.8.0 < 1.9.0affected
AutodeskAutoCAD2025.0.0 < 2025.1.4affected
AutodeskAutoCAD2024.0.0 < 2024.1.9affected

Weaknesses

  • CWE-787: CWE-787 Out-of-Bounds Write

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References