CVE-2025-1432: 3DM File Parsing Use-After-Free Vulnerability
A maliciously crafted 3DM file, when parsed through Autodesk AutoCAD, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1432?
CVE-2025-1432 has a high severity rating due to its potential to allow arbitrary code execution.
How do I fix CVE-2025-1432?
To fix CVE-2025-1432, ensure you have installed the latest security update provided by Autodesk for AutoCAD.
What versions of Autodesk AutoCAD are affected by CVE-2025-1432?
CVE-2025-1432 affects Autodesk AutoCAD 2024.
What can a malicious actor do with CVE-2025-1432?
A malicious actor can exploit CVE-2025-1432 to crash the application, read sensitive data, or execute arbitrary code.
Is there a workaround for CVE-2025-1432 while waiting for a patch?
Currently, disconnecting from untrusted sources and avoiding opening unverified 3DM files can serve as a temporary workaround for CVE-2025-1432.