Junglewise Threat Intelligence

CVE-2026-1288: Autodesk Revit NULL Pointer Dereference in Convert RFA to FormIt

CVE-2026-1288 · Severity: medium · CVSS 5.5 · Published 2026-06-17

Technologies: Autodesk Revit. Vendors: Autodesk.

Executive brief

Autodesk Revit is a professional design software used by architects and engineers to create building models. A vulnerability exists where opening a specially crafted RFA file and using the "Convert RFA to FormIt" feature can cause the application to crash. This results in a denial-of-service, potentially causing users to lose unsaved work or disrupting project workflows.

Technical details

A NULL Pointer Dereference (CWE-476) exists within Autodesk Revit when processing RFA files through the “Convert RFA to FormIt” conversion utility. The vulnerability is triggered when the application attempts to read or process a specifically malformed RFA file, leading to an invalid memory access and subsequent process termination. This is a local attack requiring user interaction, as a user must be persuaded to open and convert the malicious file. Successful exploitation results in a denial-of-service (DoS) condition of the Revit application. Patches have been released for versions 2024 through 2027.

Affected products

  • Autodesk Revit 2027.0.0 before 2027.1.0, 2026.0.0 before 2026.4.1, 2025.0.0 before 2025.4.5, 2024.0.0 before 2024.3.5

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory

References

Related threats