A maliciously crafted DGN file, when linked or imported into Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
2025-08-15T15:15:32.973
2025-08-20T21:21:15.320
Analyzed
CVSSv3.1: 7.8 (HIGH)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | autodesk | advance_steel | 2026 | Yes |
| Application | autodesk | autocad | 2026 | Yes |
| Application | autodesk | autocad_architecture | 2026 | Yes |
| Application | autodesk | autocad_electrical | 2026 | Yes |
| Application | autodesk | autocad_lt | 2026 | Yes |
| Application | autodesk | autocad_map_3d | 2026 | Yes |
| Application | autodesk | autocad_mechanical | 2026 | Yes |
| Application | autodesk | autocad_mep | 2026 | Yes |
| Application | autodesk | autocad_plant_3d | 2026 | Yes |
| Application | autodesk | civil_3d | 2026 | Yes |