CVE-2025-5036: RFA File Parsing Use-After-Free Vulnerability
Published Jun 2, 2025
·Updated
A maliciously crafted RFA file, when linked or imported into Autodesk Revit, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
Affected Software
4 affected components
Autodesk Revit
Autodesk Revit>=2024<2024.3.3
Autodesk Revit>=2025<2025.4.2
Autodesk Revit>=2026<2026.1
Event History
Jun 2, 2025
CVE Published
via MITRE·04:55 PM
Data Sourced
via MITRE·04:55 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-5036?
CVE-2025-5036 is considered a critical vulnerability due to its potential to allow arbitrary code execution.
2
How do I fix CVE-2025-5036?
To mitigate CVE-2025-5036, update Autodesk Revit to the latest version provided by Autodesk.
3
What effects can CVE-2025-5036 have on my system?
CVE-2025-5036 can lead to crashes, exposure of sensitive data, and execution of arbitrary code.
4
What types of files are associated with CVE-2025-5036?
CVE-2025-5036 is associated with maliciously crafted RFA files.
5
How can I protect against CVE-2025-5036?
To protect against CVE-2025-5036, avoid opening untrusted RFA files and ensure your Autodesk Revit is always updated.