CVE-2025-1274

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Apr 15, 2025
Updated: May 8, 2025
CWE ID 787

Summary

CVE-2025-1274 is a newly disclosed vulnerability that affects Autodesk Revit. Maliciously crafted RCS files can exploit this issue, leading to an Out-of-Bounds Write condition. This vulnerability poses a significant risk, as an attacker could exploit it to cause a crash, corrupt data, or even execute arbitrary code in the context of the current process. While parsing an affected RCS file in Autodesk Revit, the software fails to properly validate input, leading to this vulnerability. Mitigation measures include updating to the latest version of Autodesk Revit and implementing file type restrictions to prevent the loading of RCS files.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share