ZDI-CAN-25767: ZDI-25-161: Autodesk AutoCAD CATPART File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autodesk AutoCAD. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2025-1428.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-25767?
ZDI-CAN-25767 has been assigned a critical CVSS rating due to its potential for remote code execution.
How do I fix ZDI-CAN-25767?
To address ZDI-CAN-25767, users should update Autodesk AutoCAD to the latest version provided by Autodesk.
What software is affected by ZDI-CAN-25767?
ZDI-CAN-25767 specifically affects Autodesk AutoCAD 2024 installations.
What is the exploit method for ZDI-CAN-25767?
ZDI-CAN-25767 requires user interaction, typically involving the opening of a malicious file or visiting a malicious webpage.
Are there any known active exploits for ZDI-CAN-25767?
There are no public reports of active exploits for ZDI-CAN-25767 at this time, but the vulnerability remains critical.