ZDI-25-160: Autodesk AutoCAD MODEL File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autodesk AutoCAD. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2025-1429.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-25-160?
The severity of ZDI-25-160 is determined by the CVSS rating assigned by the ZDI, reflecting the potential impact of the vulnerability.
How do I fix ZDI-25-160?
To fix ZDI-25-160, users should install the latest security updates provided by Autodesk for AutoCAD.
What systems are affected by ZDI-25-160?
ZDI-25-160 affects installations of Autodesk AutoCAD, specifically Autodesk AutoCAD 2024.
Is user interaction required to exploit ZDI-25-160?
Yes, user interaction is required to exploit ZDI-25-160 by visiting a malicious page or opening a malicious file.
What type of attacks does ZDI-25-160 allow?
ZDI-25-160 allows remote attackers to execute arbitrary code on the affected installations of Autodesk AutoCAD.