A maliciously crafted 3DM file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
Metrics
Affected Vendors & Products
References
History
Mon, 04 Aug 2025 14:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Autodesk 3ds Max
Autodesk advance Steel Autodesk autocad Autodesk autocad Architecture Autodesk autocad Electrical Autodesk autocad Map 3d Autodesk autocad Mechanical Autodesk autocad Mep Autodesk autocad Plant 3d Autodesk civil 3d Autodesk infraworks Autodesk inventor Autodesk revit Autodesk revit Lt Autodesk shared Components Autodesk vault |
|
CPEs | cpe:2.3:a:autodesk:3ds_max:2026:*:*:*:*:*:*:* cpe:2.3:a:autodesk:advance_steel:2026:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad:2026:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_architecture:2026:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_electrical:2026:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_map_3d:2026:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_mechanical:2026:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_mep:2026:*:*:*:*:*:*:* cpe:2.3:a:autodesk:autocad_plant_3d:2026:*:*:*:*:*:*:* cpe:2.3:a:autodesk:civil_3d:2026:*:*:*:*:*:*:* cpe:2.3:a:autodesk:infraworks:2026:-:*:*:*:*:*:* cpe:2.3:a:autodesk:inventor:2026:*:*:*:*:*:*:* cpe:2.3:a:autodesk:revit:2026:*:*:*:*:*:*:* cpe:2.3:a:autodesk:revit_lt:2026:*:*:*:*:*:*:* cpe:2.3:a:autodesk:shared_components:2026.2:*:*:*:*:*:*:* cpe:2.3:a:autodesk:vault:2026:*:*:*:*:*:*:* |
|
Vendors & Products |
Autodesk 3ds Max
Autodesk advance Steel Autodesk autocad Autodesk autocad Architecture Autodesk autocad Electrical Autodesk autocad Map 3d Autodesk autocad Mechanical Autodesk autocad Mep Autodesk autocad Plant 3d Autodesk civil 3d Autodesk infraworks Autodesk inventor Autodesk revit Autodesk revit Lt Autodesk shared Components Autodesk vault |
Wed, 30 Jul 2025 11:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Autodesk
Autodesk autodesk |
|
Vendors & Products |
Autodesk
Autodesk autodesk |
Tue, 29 Jul 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 29 Jul 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A maliciously crafted 3DM file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process. | |
Title | 3DM File Parsing Out-of-Bounds Write Vulnerability | |
Weaknesses | CWE-787 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: autodesk
Published: 2025-07-29T17:57:36.134Z
Updated: 2025-07-30T03:55:57.025Z
Reserved: 2025-07-15T12:31:56.589Z
Link: CVE-2025-7675

Updated: 2025-07-29T18:29:01.003Z

Status : Analyzed
Published: 2025-07-29T18:15:32.923
Modified: 2025-08-04T13:49:29.270
Link: CVE-2025-7675

No data.