CVE-2025-1274: RCS File Parsing Out-of-Bounds Write Vulnerability
Published Apr 15, 2025
·Updated
A maliciously crafted RCS file, when parsed through Autodesk Revit, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
Affected Software
4 affected components
Autodesk Revit
Autodesk Revit>=2023<2023.1.7
Autodesk Revit>=2024<2024.3.2
Autodesk Revit>=2025<2025.4.1
Event History
Apr 15, 2025
CVE Published
via MITRE·08:58 PM
Data Sourced
via MITRE·08:58 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-1274?
CVE-2025-1274 has a high severity rating due to its potential to cause data corruption and execute arbitrary code.
2
How do I fix CVE-2025-1274?
To mitigate CVE-2025-1274, ensure that you have applied the latest security updates provided by Autodesk for Revit.
3
What software is affected by CVE-2025-1274?
CVE-2025-1274 specifically affects Autodesk Revit 2025.
4
What can a malicious actor achieve with CVE-2025-1274?
A malicious actor can leverage CVE-2025-1274 to cause a crash or execute arbitrary code within Autodesk Revit.
5
Is CVE-2025-1274 an out-of-bounds write vulnerability?
Yes, CVE-2025-1274 is classified as an out-of-bounds write vulnerability.