CVE-2025-1274
CVSS 3.1 Score 7.8 of 10 (high)
Details
Summary
CVE-2025-1274 is a newly disclosed vulnerability that affects Autodesk Revit. Maliciously crafted RCS files can exploit this issue, leading to an Out-of-Bounds Write condition. This vulnerability poses a significant risk, as an attacker could exploit it to cause a crash, corrupt data, or even execute arbitrary code in the context of the current process. While parsing an affected RCS file in Autodesk Revit, the software fails to properly validate input, leading to this vulnerability. Mitigation measures include updating to the latest version of Autodesk Revit and implementing file type restrictions to prevent the loading of RCS files.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Autodesk Revit
Affected Vendors
- Autodesk