CVE-2025-5040

A maliciously crafted RTE file, when parsed through Autodesk Revit, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:autodesk:revit:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:revit:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:revit:*:*:*:*:*:*:*:*

History

19 Aug 2025, 14:15

Type Values Removed Values Added
References
  • () https://www.autodesk.com/products/autodesk-access/overview -

22 Jul 2025, 16:50

Type Values Removed Values Added
References () https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0012 - () https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0012 - Vendor Advisory
First Time Autodesk
Autodesk revit
Summary
  • (es) Un archivo RTE manipulado con fines maliciosos, al analizarse mediante Autodesk Revit, puede generar una vulnerabilidad de desbordamiento basado en montón. Un agente malicioso puede aprovechar esta vulnerabilidad para provocar un bloqueo, leer datos confidenciales o ejecutar código arbitrario en el contexto del proceso actual.
CPE cpe:2.3:a:autodesk:revit:*:*:*:*:*:*:*:*

10 Jul 2025, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-10 12:15

Updated : 2025-08-19 14:15


NVD link : CVE-2025-5040

Mitre link : CVE-2025-5040

CVE.ORG link : CVE-2025-5040


JSON object : View

Products Affected

autodesk

  • revit
CWE
CWE-122

Heap-based Buffer Overflow