CVE-2023-25002: Use After Free
A maliciously crafted SKP file in Autodesk products is used to trigger use-after-free vulnerability. Exploitation of this vulnerability may lead to code execution.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-25002?
CVE-2023-25002 is a vulnerability in Autodesk products that allows a maliciously crafted SKP file to trigger a use-after-free vulnerability, potentially leading to code execution.
Which Autodesk products are affected by CVE-2023-25002?
Autodesk 3ds Max 2022 and 2023, Autodesk Navisworks 2022 and 2023, Autodesk Revit 2022 and 2023, and Autodesk VRED 2023 are all affected by CVE-2023-25002.
How severe is CVE-2023-25002?
CVE-2023-25002 has a severity score of 7.8 (high).
How can CVE-2023-25002 be exploited?
CVE-2023-25002 can be exploited by using a specially crafted SKP file in Autodesk products.
Is there a fix for CVE-2023-25002?
Autodesk has released a security advisory (ADSK-SA-2023-0002) with information on how to mitigate the vulnerability. Please refer to their website for the necessary steps.