cbcvebase.
CVE-2025-5039
published 2025-07-24

CVE-2025-5039: A maliciously crafted binary file, when present while loading files in certain Autodesk applications, could lead to execution of arbitrary code in the context…

PriorityP338high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.18%
7.3th percentile
A maliciously crafted binary file, when present while loading files in certain Autodesk applications, could lead to execution of arbitrary code in the context of the current process due to an untrusted search path being utilized.

Affected

11 ranges
VendorProductVersion rangeFixed in
autodesk3ds_max>= 2026 < 2026.3.32026.3.3
autodesk3ds_max>= 2027 < 2027.12027.1
autodeskautocad>= 2026 < 2026.12026.1
autodeskautocad_lt>= 2026 < 2026.12026.1
autodeskinfrastructure_parts_editor>= 2026 < 2026.0.22026.0.2
autodeskinventor>= 2026 < 2026.0.22026.0.2
autodesknavisworks_manage>= 2026 < 2026.0.22026.0.2
autodesknavisworks_simulate>= 2026 < 2026.0.22026.0.2
autodeskrealdwg>= 2026 < 2026.0.22026.0.2
autodeskrevit>= 2026 < 2026.0.22026.0.2
autodeskvault>= 2026 < 2026.0.22026.0.2
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.