Executive brief
A maliciously crafted CATPRODUCT file can trigger a heap-based overflow in certain Autodesk products when parsed. An attacker can exploit this vulnerability to crash the application, steal sensitive data, or execute arbitrary code with the permissions of the affected user, impacting design workflows and data security.
Technical details
This vulnerability is a heap-based buffer overflow in the CATPRODUCT file parsing functionality of certain Autodesk products. The vulnerability is triggered when a crafted CATPRODUCT file is opened or processed, causing memory corruption in the heap. Attack preconditions include the victim opening a malicious CATPRODUCT file, typically via local or network file access. Successful exploitation allows arbitrary code execution in the context of the Autodesk application process, potentially leading to data exfiltration or lateral movement within the victim's environment. Patch availability is currently unknown based on the advisory text.
Affected products
- Autodesk <UNKNOWN>
Timeline
- 2025-12-16: disclosed