CVE-2025-1277

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Apr 15, 2025
Updated: May 8, 2025
CWE ID 787
CWE ID 120

Summary

CVE-2025-1277 is a newly discovered memory corruption vulnerability that affects Autodesk applications. Maliciously crafted PDF files can exploit this weakness, leading to arbitrary code execution in the context of the current process. An attacker can potentially leverage this vulnerability by creating and distributing a malicious PDF file to gain unauthorized access to a victim's system. The precise method of exploitation involves parsing the PDF file through Autodesk applications, resulting in memory corruption that allows for code injection. Organizations using Autodesk applications are advised to apply patches or updates as soon as they become available to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share