CVE-2025-1276

A maliciously crafted DWG file, when parsed through certain Autodesk applications, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad:*:*:*:*:*:-:*:*
cpe:2.3:a:autodesk:autocad:*:*:*:*:*:-:*:*
cpe:2.3:a:autodesk:autocad:*:*:*:*:*:-:*:*
cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:-:*:*
cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:-:*:*
cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:-:*:*
cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:dwg_trueview:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:dwg_trueview:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:dwg_trueview:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:infrastructure_parts_editor:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:infrastructure_parts_editor:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:inventor:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:inventor:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:navisworks_manage:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:navisworks_manage:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:navisworks_simulate:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:navisworks_simulate:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:revit:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:revit:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:vault:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:vault:*:*:*:*:*:*:*:*

History

30 Jul 2025, 17:25

Type Values Removed Values Added
References () https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0004 - () https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0004 - Vendor Advisory
CPE cpe:2.3:a:autodesk:revit:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:navisworks_simulate:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:inventor:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:vault:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:infrastructure_parts_editor:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:navisworks_manage:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:-:*:*
cpe:2.3:a:autodesk:dwg_trueview:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad:*:*:*:*:*:-:*:*
First Time Autodesk autocad Mechanical
Autodesk advance Steel
Autodesk navisworks Simulate
Autodesk autocad Electrical
Autodesk navisworks Manage
Autodesk autocad Architecture
Autodesk infrastructure Parts Editor
Autodesk vault
Autodesk autocad Mep
Autodesk
Autodesk revit
Autodesk dwg Trueview
Autodesk autocad Lt
Autodesk inventor
Autodesk civil 3d
Autodesk autocad Plant 3d
Autodesk autocad Map 3d
Autodesk autocad

16 Apr 2025, 13:25

Type Values Removed Values Added
Summary
  • (es) Un archivo DWG manipulado con fines maliciosos, al analizarse mediante ciertas aplicaciones de Autodesk, puede forzar una vulnerabilidad de escritura fuera de los límites. Un agente malicioso podría aprovechar esta vulnerabilidad para provocar un bloqueo, dañar datos o ejecutar código arbitrario en el contexto del proceso actual.

15 Apr 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-15 21:15

Updated : 2025-07-30 17:25


NVD link : CVE-2025-1276

Mitre link : CVE-2025-1276

CVE.ORG link : CVE-2025-1276


JSON object : View

Products Affected

autodesk

  • advance_steel
  • autocad_lt
  • autocad
  • dwg_trueview
  • autocad_plant_3d
  • autocad_mechanical
  • autocad_mep
  • navisworks_simulate
  • inventor
  • revit
  • vault
  • infrastructure_parts_editor
  • autocad_architecture
  • autocad_map_3d
  • civil_3d
  • navisworks_manage
  • autocad_electrical
CWE
CWE-787

Out-of-bounds Write