CVE-2025-5039

A maliciously crafted binary file, when present while loading files in certain Autodesk applications, could lead to execution of arbitrary code in the context of the current process due to an untrusted search path being utilized.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:autodesk:infrastructure_parts_editor:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:inventor:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:navisworks_manage:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:navisworks_simulate:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:revit:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:vault:*:*:*:*:*:*:*:*

History

19 Aug 2025, 14:15

Type Values Removed Values Added
References
  • () https://www.autodesk.com/products/autodesk-access/overview -

30 Jul 2025, 17:45

Type Values Removed Values Added
References () https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0014 - () https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0014 - Vendor Advisory
First Time Autodesk
Autodesk navisworks Simulate
Autodesk vault
Autodesk navisworks Manage
Autodesk inventor
Autodesk infrastructure Parts Editor
Autodesk revit
CPE cpe:2.3:a:autodesk:infrastructure_parts_editor:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:revit:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:navisworks_manage:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:vault:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:navisworks_simulate:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:inventor:*:*:*:*:*:*:*:*
Summary
  • (es) Un archivo binario manipulado con fines malintencionados, cuando está presente durante la carga de archivos en ciertas aplicaciones de Autodesk, podría provocar la ejecución de código arbitrario en el contexto del proceso actual debido al uso de una ruta de búsqueda no confiable.

24 Jul 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-24 17:15

Updated : 2025-08-19 14:15


NVD link : CVE-2025-5039

Mitre link : CVE-2025-5039

CVE.ORG link : CVE-2025-5039


JSON object : View

Products Affected

autodesk

  • vault
  • navisworks_simulate
  • inventor
  • infrastructure_parts_editor
  • navisworks_manage
  • revit
CWE
CWE-426

Untrusted Search Path