CVE-2025-5038

A maliciously crafted X_T file, when parsed through certain Autodesk products, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:autodesk:shared_components:2026.2:*:*:*:*:*:*:*
OR cpe:2.3:a:autodesk:3ds_max:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:advance_steel:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_architecture:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_electrical:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_map_3d:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_mechanical:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_mep:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_plant_3d:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:civil_3d:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:infraworks:2026:-:*:*:*:*:*:*
cpe:2.3:a:autodesk:inventor:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:revit:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:revit_lt:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:vault:2026:*:*:*:*:*:*:*

History

19 Aug 2025, 14:15

Type Values Removed Values Added
References
  • () https://www.autodesk.com/products/autodesk-access/overview -

04 Aug 2025, 14:10

Type Values Removed Values Added
First Time Autodesk
Autodesk vault
Autodesk autocad Map 3d
Autodesk autocad Architecture
Autodesk infraworks
Autodesk revit Lt
Autodesk advance Steel
Autodesk civil 3d
Autodesk autocad
Autodesk autocad Mechanical
Autodesk autocad Electrical
Autodesk 3ds Max
Autodesk autocad Plant 3d
Autodesk revit
Autodesk autocad Mep
Autodesk shared Components
Autodesk inventor
CPE cpe:2.3:a:autodesk:3ds_max:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_architecture:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_map_3d:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:infraworks:2026:-:*:*:*:*:*:*
cpe:2.3:a:autodesk:inventor:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:revit_lt:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_electrical:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:civil_3d:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_plant_3d:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:shared_components:2026.2:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_mechanical:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:vault:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:advance_steel:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:revit:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_mep:2026:*:*:*:*:*:*:*
References () https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0015 - () https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0015 - Vendor Advisory

31 Jul 2025, 18:42

Type Values Removed Values Added
Summary
  • (es) Un archivo X_T manipulado con fines maliciosos, al analizarse mediante ciertos productos de Autodesk, puede generar una vulnerabilidad de corrupción de memoria. Un agente malicioso puede aprovechar esta vulnerabilidad para ejecutar código arbitrario en el contexto del proceso actual.

29 Jul 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-29 18:15

Updated : 2025-08-19 14:15


NVD link : CVE-2025-5038

Mitre link : CVE-2025-5038

CVE.ORG link : CVE-2025-5038


JSON object : View

Products Affected

autodesk

  • infraworks
  • inventor
  • autocad_mep
  • autocad
  • autocad_architecture
  • revit
  • revit_lt
  • autocad_plant_3d
  • vault
  • shared_components
  • autocad_electrical
  • autocad_map_3d
  • autocad_mechanical
  • advance_steel
  • civil_3d
  • 3ds_max
CWE
CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')