CVE-2025-5039

Published Jul 24, 2025

Last updated 7 months ago

Overview

Description
A maliciously crafted binary file, when present while loading files in certain Autodesk applications, could lead to execution of arbitrary code in the context of the current process due to an untrusted search path being utilized.
Source
psirt@autodesk.com
NVD status
Analyzed
Products
infrastructure_parts_editor, inventor, navisworks_manage, navisworks_simulate, revit, vault

Risk scores

CVSS 3.1

Type
Primary
Base score
7.8
Impact score
5.9
Exploitability score
1.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

psirt@autodesk.com
CWE-426

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.