ZDI-25-156: Autodesk AutoCAD SLDPRT File Parsing Memory Corruption Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autodesk AutoCAD. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2025-1430.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-25-156?
The ZDI-25-156 vulnerability has a moderate severity rating based on its potential impact on Autodesk AutoCAD installations.
How do I fix ZDI-25-156?
To fix ZDI-25-156, ensure that you update Autodesk AutoCAD to the latest version provided by Autodesk.
What types of attacks can ZDI-25-156 facilitate?
ZDI-25-156 allows remote attackers to execute arbitrary code by leveraging user interaction with a malicious page or file.
What versions of Autodesk AutoCAD are affected by ZDI-25-156?
ZDI-25-156 specifically affects Autodesk AutoCAD 2024.
Is user interaction required for exploiting ZDI-25-156?
Yes, user interaction is required to exploit ZDI-25-156, as the target must visit a malicious page or open a malicious file.