CVE-2025-1649: CATPRODUCT File Parsing Uninitialized Variable Vulnerability
A maliciously crafted CATPRODUCT file, when parsed through Autodesk AutoCAD, can force an Uninitialized Variable vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1649?
CVE-2025-1649 is considered a critical vulnerability due to its potential to allow arbitrary code execution and access to sensitive data.
How do I fix CVE-2025-1649?
To remediate CVE-2025-1649, Autodesk recommends updating AutoCAD to the latest version where the vulnerability has been patched.
What products are affected by CVE-2025-1649?
CVE-2025-1649 affects Autodesk AutoCAD 2024 and likely other versions within the same software family.
Can CVE-2025-1649 be exploited remotely?
Exploitation of CVE-2025-1649 requires local access to the system, as it involves parsing a malicious CATPRODUCT file.
What are the potential consequences of CVE-2025-1649?
If exploited, CVE-2025-1649 can lead to system crashes, exposure of sensitive data, or execution of arbitrary code in the context of the current process.