CVE-2025-5039
published 2025-07-24CVE-2025-5039: A maliciously crafted binary file, when present while loading files in certain Autodesk applications, could lead to execution of arbitrary code in the context…
high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
A maliciously crafted binary file, when present while loading files in certain Autodesk applications, could lead to execution of arbitrary code in the context of the current process due to an untrusted search path being utilized.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| autodesk | 3ds_max | >= 2026 < 2026.3.3 | 2026.3.3 |
| autodesk | 3ds_max | >= 2027 < 2027.1 | 2027.1 |
| autodesk | autocad | >= 2026 < 2026.1 | 2026.1 |
| autodesk | autocad_lt | >= 2026 < 2026.1 | 2026.1 |
| autodesk | infrastructure_parts_editor | >= 2026 < 2026.0.2 | 2026.0.2 |
| autodesk | inventor | >= 2026 < 2026.0.2 | 2026.0.2 |
| autodesk | navisworks_manage | >= 2026 < 2026.0.2 | 2026.0.2 |
| autodesk | navisworks_simulate | >= 2026 < 2026.0.2 | 2026.0.2 |
| autodesk | realdwg | >= 2026 < 2026.0.2 | 2026.0.2 |
| autodesk | revit | >= 2026 < 2026.0.2 | 2026.0.2 |
| autodesk | vault | >= 2026 < 2026.0.2 | 2026.0.2 |