CVE-2025-6631

A maliciously crafted PRT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:autodesk:shared_components:2026.2:*:*:*:*:*:*:*
OR cpe:2.3:a:autodesk:3ds_max:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:advance_steel:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_architecture:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_electrical:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_map_3d:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_mechanical:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_mep:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_plant_3d:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:civil_3d:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:infraworks:2026:-:*:*:*:*:*:*
cpe:2.3:a:autodesk:inventor:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:revit:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:revit_lt:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:vault:2026:*:*:*:*:*:*:*

History

04 Aug 2025, 14:09

Type Values Removed Values Added
CPE cpe:2.3:a:autodesk:autocad_map_3d:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:vault:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_electrical:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_mechanical:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:inventor:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:advance_steel:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_plant_3d:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:revit_lt:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_mep:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:3ds_max:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:shared_components:2026.2:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:infraworks:2026:-:*:*:*:*:*:*
cpe:2.3:a:autodesk:revit:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_architecture:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:civil_3d:2026:*:*:*:*:*:*:*
References () https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0015 - () https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0015 - Vendor Advisory
First Time Autodesk infraworks
Autodesk autocad
Autodesk civil 3d
Autodesk revit Lt
Autodesk 3ds Max
Autodesk autocad Electrical
Autodesk
Autodesk autocad Mechanical
Autodesk autocad Architecture
Autodesk autocad Map 3d
Autodesk shared Components
Autodesk inventor
Autodesk vault
Autodesk autocad Mep
Autodesk advance Steel
Autodesk revit
Autodesk autocad Plant 3d

31 Jul 2025, 18:42

Type Values Removed Values Added
Summary
  • (es) Un archivo PRT manipulado con fines maliciosos, al analizarse mediante ciertos productos de Autodesk, puede forzar una vulnerabilidad de escritura fuera de los límites. Un agente malicioso podría aprovechar esta vulnerabilidad para provocar un bloqueo, dañar datos o ejecutar código arbitrario en el contexto del proceso actual.

29 Jul 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-29 18:15

Updated : 2025-08-04 14:09


NVD link : CVE-2025-6631

Mitre link : CVE-2025-6631

CVE.ORG link : CVE-2025-6631


JSON object : View

Products Affected

autodesk

  • shared_components
  • autocad_map_3d
  • 3ds_max
  • autocad_mep
  • autocad_plant_3d
  • autocad_architecture
  • infraworks
  • autocad_mechanical
  • revit
  • advance_steel
  • autocad
  • revit_lt
  • vault
  • civil_3d
  • autocad_electrical
  • inventor
CWE
CWE-787

Out-of-bounds Write