CVE-2025-5039

A maliciously crafted binary file, when present while loading files in certain Autodesk applications, could lead to execution of arbitrary code in the context of the current process due to an untrusted search path being utilized.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
autodeskCNA
7.8 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 4%
VendorProductVersion
autodeskinfrastructure_parts_editor
2026 ≤
𝑥
< 2026.0.2
autodeskinventor
2026 ≤
𝑥
< 2026.0.2
autodesknavisworks_manage
2026 ≤
𝑥
< 2026.0.2
autodesknavisworks_simulate
2026 ≤
𝑥
< 2026.0.2
autodeskrevit
2026 ≤
𝑥
< 2026.0.2
autodeskvault
2026 ≤
𝑥
< 2026.0.2
𝑥
= Vulnerable software versions