ZDI-25-1111: Autodesk AutoCAD CATPRODUCT File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autodesk AutoCAD. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2025-10883.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-25-1111?
ZDI-25-1111 has been assigned a CVSS rating indicating a significant risk due to its potential for arbitrary code execution.
How do I fix ZDI-25-1111?
To mitigate ZDI-25-1111, ensure that you apply the latest security updates provided by Autodesk for AutoCAD.
What are the affected versions for ZDI-25-1111?
ZDI-25-1111 affects specific installations of Autodesk AutoCAD, though exact affected versions should be confirmed through Autodesk's security advisories.
What type of attack vector is associated with ZDI-25-1111?
ZDI-25-1111 can be exploited through user interaction by visiting malicious pages or opening harmful files.
Who is responsible for disclosing ZDI-25-1111?
The Zero Day Initiative (ZDI) disclosed the ZDI-25-1111 vulnerability after its discovery.