Junglewise Threat Intelligence

CVE-2025-10898: Autodesk products out-of-bounds write in MODEL file parsing

CVE-2025-10898 · Severity: high · CVSS 7.8 · Published 2025-12-16

Technologies: Autodesk AutoCAD, Autodesk 3ds Max, Autodesk <UNKNOWN>, Autodesk Revit. Vendors: Autodesk.

Executive brief

Autodesk products that parse MODEL files are vulnerable to an out-of-bounds write when processing maliciously crafted files. An attacker can exploit this by tricking a user into opening a malicious MODEL file, potentially causing the application to crash, corrupt data, or execute arbitrary code with the privileges of the user running the application.

Technical details

This vulnerability is a heap or stack-based out-of-bounds write triggered during the parsing of specially crafted MODEL files in Autodesk products. The root cause lies in improper bounds checking or buffer management during file parsing. The attack vector is local and requires user interaction to open a malicious MODEL file. A successful exploit allows an attacker to cause denial of service, data corruption, or achieve arbitrary code execution in the context of the vulnerable application. Patches or mitigation details are not yet available from the vendor documentation reviewed.

Affected products

  • Autodesk <UNKNOWN> <UNKNOWN>

Timeline

  • 2025-12-16: disclosed

References

Related threats