CVE-2025-5039

CWE-4263 documents3 sources
Severity
7.8HIGH
EPSS
0.0%
top 85.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 24

Description

A maliciously crafted binary file, when present while loading files in certain Autodesk applications, could lead to execution of arbitrary code in the context of the current process due to an untrusted search path being utilized.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages17 packages

NVDautodesk/revit20262026.0.2
NVDautodesk/vault20262026.0.2
CVEListV5autodesk/autocad20262026.1
CVEListV5autodesk/realdwg20262026.0.2
CVEListV5autodesk/civil_3d20262026.1

🔴Vulnerability Details

2
GHSA
GHSA-4c85-w99g-9v4w: A maliciously crafted binary file, when present while loading files in certain Autodesk applications, could lead to execution of arbitrary code in the2025-07-24
CVEList
Privilege Ecalation due to Untrusted Search Path Vulnerability2025-07-24
CVE-2025-5039 (HIGH CVSS 7.8) | A maliciously crafted binary file | cvebase.io