First published: Tue Jun 27 2023(Updated: )
A maliciously crafted SKP file in Autodesk products is used to trigger use-after-free vulnerability. Exploitation of this vulnerability may lead to code execution.
Credit: psirt@autodesk.com
Affected Software | Affected Version | How to fix |
---|---|---|
Autodesk 3ds Max | =2022 | |
Autodesk 3ds Max | =2023 | |
Autodesk Navisworks | =2022 | |
Autodesk Navisworks | =2023 | |
Autodesk Revit | =2022 | |
Autodesk Revit | =2023 | |
Autodesk VRED | =2023 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-25002 is a vulnerability in Autodesk products that allows a maliciously crafted SKP file to trigger a use-after-free vulnerability, potentially leading to code execution.
Autodesk 3ds Max 2022 and 2023, Autodesk Navisworks 2022 and 2023, Autodesk Revit 2022 and 2023, and Autodesk VRED 2023 are all affected by CVE-2023-25002.
CVE-2023-25002 has a severity score of 7.8 (high).
CVE-2023-25002 can be exploited by using a specially crafted SKP file in Autodesk products.
Autodesk has released a security advisory (ADSK-SA-2023-0002) with information on how to mitigate the vulnerability. Please refer to their website for the necessary steps.