HIGH
SLDPRT File Parsing Out-of-Bounds Read Vulnerability
Published Dec 15, 2025
7.8
HIGHCVSS 3.1
EPSS 0.26%
Description
A maliciously crafted SLDPRT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
Affected products
-
- Version 1.8.0.7StatusaffectedConstraints<1.9.0.7
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Autodesk | Shared Components | unaffected |
|
AND
- < 2026.5
Running on/with
OR
- 2026
- 2026
- 2026
- 2026
- 2026
- 2026
- 2026
- 2026
- 2026
- 2026
- 2026
- 2026
- 2026
- 2026
- 2026
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://www.autodesk.com/products/autodesk-access/overview patchProduct
- https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0024 vendor-advisoryVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://www.autodesk.com/products/autodesk-access/overview | patchProduct | |
| https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0024 | vendor-advisoryVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner autodesk
Published Dec 15, 2025
Updated May 8, 2026
Reserved Aug 25, 2025
Link CVE-2025-9459
CISA Vulnrichment
Updated Dec 17, 2025