A maliciously crafted 3DM file, when parsed through Autodesk AutoCAD, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
|
Configuration 6 (hide)
|
Configuration 7 (hide)
|
Configuration 8 (hide)
|
Configuration 9 (hide)
|
History
13 Nov 2025, 19:34
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.autodesk.com/products/autodesk-access/overview - Product | |
| References | () https://www.autodesk.com/support/technical/article/caas/sfdcarticles/sfdcarticles/Where-can-I-download-the-latest-update-of-AutoCAD-AutoCAD-LT-2022.html - Product |
Information
Published : 2025-03-13 17:15
Updated : 2025-11-13 19:34
NVD link : CVE-2025-1432
Mitre link : CVE-2025-1432
CVE.ORG link : CVE-2025-1432
JSON object : View
Products Affected
autodesk
- autocad_electrical
- autocad_map_3d
- autocad
- autocad_mep
- autocad_mechanical
- autocad_plant_3d
- autocad_architecture
- advance_steel
- civil_3d
CWE
CWE-416
Use After Free
