ZDI-CAN-28421: ZDI-25-1123: Autodesk AutoCAD CATPART File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autodesk AutoCAD. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2025-14593.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-28421?
ZDI-CAN-28421 is rated with a CVSS score indicating it poses a significant risk for remote code execution.
How do I fix ZDI-CAN-28421?
To mitigate ZDI-CAN-28421, ensure you update Autodesk AutoCAD to the latest version released by Autodesk.
What types of attacks can ZDI-CAN-28421 facilitate?
ZDI-CAN-28421 can facilitate remote code execution attacks against affected installations of Autodesk AutoCAD.
Is user interaction necessary to exploit ZDI-CAN-28421?
Yes, user interaction is required to exploit ZDI-CAN-28421, specifically through visiting a malicious page or opening a malicious file.
Who is affected by ZDI-CAN-28421?
Users of Autodesk AutoCAD are at risk from the vulnerabilities associated with ZDI-CAN-28421.