CVE-2025-5046

A maliciously crafted DGN file, when linked or imported into Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:autodesk:advance_steel:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_architecture:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_electrical:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_lt:2026:*:*:*:*:-:*:*
cpe:2.3:a:autodesk:autocad_map_3d:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_mechanical:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_mep:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_plant_3d:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:civil_3d:2026:*:*:*:*:*:*:*

History

20 Aug 2025, 21:21

Type Values Removed Values Added
First Time Autodesk autocad Electrical
Autodesk autocad
Autodesk
Autodesk autocad Mechanical
Autodesk civil 3d
Autodesk autocad Map 3d
Autodesk autocad Architecture
Autodesk autocad Mep
Autodesk advance Steel
Autodesk autocad Lt
Autodesk autocad Plant 3d
CPE cpe:2.3:a:autodesk:autocad:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:civil_3d:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_mep:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_electrical:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_mechanical:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:advance_steel:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_architecture:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_map_3d:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_plant_3d:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_lt:2026:*:*:*:*:-:*:*
References () https://www.autodesk.com/products/autodesk-access/overview - () https://www.autodesk.com/products/autodesk-access/overview - Product
References () https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0017 - () https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0017 - Vendor Advisory

18 Aug 2025, 20:16

Type Values Removed Values Added
Summary
  • (es) Un archivo DGN manipulado con fines maliciosos, al vincularse o importarse a Autodesk AutoCAD, puede forzar una vulnerabilidad de lectura fuera de los límites. Un agente malicioso puede aprovechar esta vulnerabilidad para provocar un bloqueo, leer datos confidenciales o ejecutar código arbitrario en el contexto del proceso actual.

15 Aug 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-15 15:15

Updated : 2025-08-20 21:21


NVD link : CVE-2025-5046

Mitre link : CVE-2025-5046

CVE.ORG link : CVE-2025-5046


JSON object : View

Products Affected

autodesk

  • autocad_map_3d
  • autocad_mep
  • autocad_plant_3d
  • autocad_architecture
  • autocad_mechanical
  • advance_steel
  • autocad_lt
  • autocad
  • civil_3d
  • autocad_electrical
CWE
CWE-125

Out-of-bounds Read