ZDI-25-1107: Autodesk AutoCAD MODEL File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autodesk AutoCAD. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2025-10888.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-25-1107?
ZDI-25-1107 is rated with a CVSS score indicating a high severity level due to its potential for remote code execution.
How do I fix ZDI-25-1107?
To fix ZDI-25-1107, users should update Autodesk AutoCAD to the latest version provided by Autodesk.
Who can exploit ZDI-25-1107?
ZDI-25-1107 can be exploited by remote attackers who can trick users into opening a malicious file or visiting a malicious webpage.
What are the consequences of exploiting ZDI-25-1107?
Exploiting ZDI-25-1107 can lead to arbitrary code execution, allowing attackers to take control of the affected system.
Is user interaction required to exploit ZDI-25-1107?
Yes, user interaction is required for ZDI-25-1107 exploitation, as victims must open a malicious file or visit a harmful site.