ZDI-CAN-28126: ZDI-25-1108: Autodesk AutoCAD MODEL File Parsing Memory Corruption Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autodesk AutoCAD. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2025-10886.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-28126?
The severity of ZDI-CAN-28126 is significant due to its ability to allow remote code execution.
How can I patch ZDI-CAN-28126?
To patch ZDI-CAN-28126, users need to install the latest security updates released by Autodesk for AutoCAD.
What is the impact of ZDI-CAN-28126?
The impact of ZDI-CAN-28126 can result in unauthorized remote code execution on affected installations of Autodesk AutoCAD.
What is required to exploit ZDI-CAN-28126?
Exploitation of ZDI-CAN-28126 requires user interaction such as visiting a malicious page or opening a malicious file.
Which software is affected by ZDI-CAN-28126?
ZDI-CAN-28126 affects Autodesk AutoCAD installations.