Executive brief
Autodesk products that parse IFC (Industry Foundation Classes) files can be forced to crash when processing a maliciously crafted file. IFC files are standard formats used in construction and building design workflows. An attacker can cause a denial-of-service by tricking a user into opening a specially crafted IFC file, disrupting work and potentially affecting project schedules.
Technical details
This vulnerability is an uncontrolled recursion issue in the IFC file parser used by certain Autodesk products. The parser fails to properly limit recursion depth when processing nested structures within maliciously crafted IFC files, allowing an attacker to trigger stack overflow or excessive resource consumption. Exploitation requires user interaction: a victim must open a specially crafted IFC file using a vulnerable Autodesk application. The attack results in application termination (denial-of-service); no authentication is required and the attack vector is local. Patches are expected to be available from Autodesk.
Affected products
- Autodesk <UNKNOWN>
Timeline
- 2026-09-02: disclosed