CVE-2025-5048

A maliciously crafted DGN file, when linked or imported into Autodesk AutoCAD, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:autodesk:advance_steel:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_architecture:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_electrical:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_lt:2026:*:*:*:*:-:*:*
cpe:2.3:a:autodesk:autocad_map_3d:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_mechanical:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_mep:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_plant_3d:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:civil_3d:2026:*:*:*:*:*:*:*

History

20 Aug 2025, 21:22

Type Values Removed Values Added
CPE cpe:2.3:a:autodesk:advance_steel:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_electrical:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_map_3d:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_lt:2026:*:*:*:*:-:*:*
cpe:2.3:a:autodesk:autocad_mep:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:civil_3d:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_plant_3d:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_mechanical:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_architecture:2026:*:*:*:*:*:*:*
References () https://www.autodesk.com/products/autodesk-access/overview - () https://www.autodesk.com/products/autodesk-access/overview - Product
References () https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0017 - () https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0017 - Vendor Advisory
First Time Autodesk civil 3d
Autodesk autocad Architecture
Autodesk advance Steel
Autodesk autocad Mep
Autodesk autocad Map 3d
Autodesk autocad Lt
Autodesk autocad Mechanical
Autodesk autocad Plant 3d
Autodesk autocad Electrical
Autodesk
Autodesk autocad

18 Aug 2025, 20:16

Type Values Removed Values Added
Summary
  • (es) Un archivo DGN manipulado con fines maliciosos, al vincularse o importarse a Autodesk AutoCAD, puede generar una vulnerabilidad de corrupción de memoria. Un agente malicioso puede aprovechar esta vulnerabilidad para ejecutar código arbitrario en el contexto del proceso actual.

15 Aug 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-15 15:15

Updated : 2025-08-20 21:22


NVD link : CVE-2025-5048

Mitre link : CVE-2025-5048

CVE.ORG link : CVE-2025-5048


JSON object : View

Products Affected

autodesk

  • civil_3d
  • autocad_mechanical
  • autocad_electrical
  • autocad_architecture
  • autocad_lt
  • advance_steel
  • autocad_map_3d
  • autocad_plant_3d
  • autocad_mep
  • autocad
CWE
CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')