ZDI-25-1112: Autodesk AutoCAD X_T File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autodesk AutoCAD. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2025-10882.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-25-1112?
ZDI-25-1112 has been assigned a CVSS rating which indicates a high severity level due to its potential for remote code execution.
How do I fix ZDI-25-1112?
To fix ZDI-25-1112, ensure that you update Autodesk AutoCAD to the latest version provided by the vendor, which includes necessary security patches.
What software is affected by ZDI-25-1112?
ZDI-25-1112 affects Autodesk AutoCAD installations that have not been updated to address this vulnerability.
Who can exploit ZDI-25-1112?
Remote attackers can exploit ZDI-25-1112, but user interaction is required, such as visiting a malicious website or opening a malicious file.
What are the potential consequences of ZDI-25-1112 exploitation?
Exploitation of ZDI-25-1112 can lead to arbitrary code execution on affected systems, potentially allowing attackers to take full control.