Executive brief
Autodesk AutoCAD and related design software are susceptible to a vulnerability when opening specially crafted drawing files. If a user opens a malicious DWG or DXF file, it could cause the application to crash or potentially allow the unauthorized disclosure of sensitive information. This could disrupt design operations or lead to the theft of intellectual property contained within the system's memory.
Technical details
An Out-of-Bounds Read vulnerability (CWE-125) exists in Autodesk AutoCAD, AutoCAD LT, and DWG TrueView when parsing maliciously crafted DWG or DXF files. The issue occurs because the application does not properly validate input data before reading from a memory buffer. An attacker can exploit this by tricking a user into opening a specially crafted file (Local attack vector, User Interaction required). Successful exploitation can lead to a Denial of Service (application crash) or the disclosure of sensitive information from the process memory. The vulnerability is addressed in version 2027.1.0.
Affected products
- Autodesk AutoCAD 2027.0.0 to 2027.1.0
- Autodesk AutoCAD LT 2027.0.0 to 2027.1.0
- Autodesk DWG TrueView 2027.0.0 to 2027.1.0
Timeline
- 2026-07-29: disclosed
- 2026-07-29: advisory