ZDI-CAN-25811: ZDI-25-159: Autodesk AutoCAD CATPRODUCT File Parsing Uninitialized Variable Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autodesk AutoCAD. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2025-1649.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-25811?
ZDI-CAN-25811 has a CVSS rating that indicates a critical severity due to the potential for remote code execution.
How do I fix ZDI-CAN-25811?
To fix ZDI-CAN-25811, you should update Autodesk AutoCAD to the latest version that addresses this vulnerability.
What impact does ZDI-CAN-25811 have on Autodesk AutoCAD?
ZDI-CAN-25811 allows remote attackers to execute arbitrary code on Autodesk AutoCAD installations.
Is user interaction required to exploit ZDI-CAN-25811?
Yes, user interaction is required as the target must visit a malicious page or open a malicious file to exploit ZDI-CAN-25811.
Which versions of Autodesk AutoCAD are affected by ZDI-CAN-25811?
ZDI-CAN-25811 specifically affects Autodesk AutoCAD 2024 installations.