cbcvebase.
CVE-2025-1427
published 2025-03-13

CVE-2025-1427: A maliciously crafted CATPRODUCT file, when parsed through Autodesk AutoCAD, can force an Uninitialized Variable vulnerability. A malicious actor can leverage…

high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
A maliciously crafted CATPRODUCT file, when parsed through Autodesk AutoCAD, can force an Uninitialized Variable vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

Affected

36 ranges· showing 25
VendorProductVersion rangeFixed in
autodeskadvance_steel>= 2022 < 2022.1.62022.1.6
autodeskadvance_steel>= 2023 < 2023.1.72023.1.7
autodeskadvance_steel>= 2024 < 2024.1.72024.1.7
autodeskadvance_steel>= 2025 < 2025.1.22025.1.2
autodeskautocad>= 2022 < 2022.1.62022.1.6
autodeskautocad>= 2023 < 2023.1.72023.1.7
autodeskautocad>= 2024 < 2024.1.72024.1.7
autodeskautocad>= 2025 < 2025.1.22025.1.2
autodeskautocad_architecture>= 2022 < 2022.1.62022.1.6
autodeskautocad_architecture>= 2023 < 2023.1.72023.1.7
autodeskautocad_architecture>= 2024 < 2024.1.72024.1.7
autodeskautocad_architecture>= 2025 < 2025.1.22025.1.2
autodeskautocad_electrical>= 2022 < 2022.1.62022.1.6
autodeskautocad_electrical>= 2023 < 2023.1.72023.1.7
autodeskautocad_electrical>= 2024 < 2024.1.72024.1.7
autodeskautocad_electrical>= 2025 < 2025.1.22025.1.2
autodeskautocad_map_3d>= 2022 < 2022.1.62022.1.6
autodeskautocad_map_3d>= 2023 < 2023.1.72023.1.7
autodeskautocad_map_3d>= 2024 < 2024.1.72024.1.7
autodeskautocad_map_3d>= 2025 < 2025.1.22025.1.2
autodeskautocad_mechanical>= 2022 < 2022.1.62022.1.6
autodeskautocad_mechanical>= 2023 < 2023.1.72023.1.7
autodeskautocad_mechanical>= 2024 < 2024.1.72024.1.7
autodeskautocad_mechanical>= 2025 < 2025.1.22025.1.2
autodeskautocad_mep>= 2022 < 2022.1.62022.1.6