CVE-2025-5039

A maliciously crafted binary file, when present while loading files in certain Autodesk applications, could lead to execution of arbitrary code in the context of the current process due to an untrusted search path being utilized.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:autodesk:infrastructure_parts_editor:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:inventor:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:navisworks_manage:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:navisworks_simulate:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:revit:*:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:vault:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-07-24 17:15

Updated : 2025-08-19 14:15


NVD link : CVE-2025-5039

Mitre link : CVE-2025-5039

CVE.ORG link : CVE-2025-5039


JSON object : View

Products Affected

autodesk

  • vault
  • infrastructure_parts_editor
  • navisworks_manage
  • navisworks_simulate
  • inventor
  • revit
CWE
CWE-426

Untrusted Search Path