CVE-2025-5039 (GCVE-0-2025-5039)
Vulnerability from cvelistv5
Published
2025-07-24 17:11
Modified
2025-08-19 13:17
CWE
Summary
A maliciously crafted binary file, when present while loading files in certain Autodesk applications, could lead to execution of arbitrary code in the context of the current process due to an untrusted search path being utilized.
Impacted products
Vendor Product Version
Autodesk AutoCAD Version: 2026   < 2026.1
    cpe:2.3:a:autodesk:autocad:2026:*:*:*:*:*:*:*
Create a notification for this product.
   Autodesk AutoCAD LT Version: 2026   < 2026.1
    cpe:2.3:a:autodesk:autocad_lt:2026:*:*:*:*:*:*:*
Create a notification for this product.
   Autodesk AutoCAD Architecture Version: 2026   < 2026.1
    cpe:2.3:a:autodesk:autocad_architecture:2026:*:*:*:*:*:*:*
Create a notification for this product.
   Autodesk AutoCAD Electrical Version: 2026   < 2026.1
    cpe:2.3:a:autodesk:autocad_electrical:2026:*:*:*:*:*:*:*
Create a notification for this product.
   Autodesk AutoCAD Mechanical Version: 2026   < 2026.1
    cpe:2.3:a:autodesk:autocad_mechanical:2026:*:*:*:*:*:*:*
Create a notification for this product.
   Autodesk AutoCAD MEP Version: 2026   < 2026.1
    cpe:2.3:a:autodesk:autocad_mep:2026:*:*:*:*:*:*:*
Create a notification for this product.
   Autodesk AutoCAD Plant 3D Version: 2026   < 2026.1
    cpe:2.3:a:autodesk:autocad_plant_3d:2026:*:*:*:*:*:*:*
Create a notification for this product.
   Autodesk AutoCAD MAP 3D Version: 2026   < 2026.1
    cpe:2.3:a:autodesk:autocad_map_3d:2026:*:*:*:*:*:*:*
Create a notification for this product.
   Autodesk Civil 3D Version: 2026   < 2026.1
    cpe:2.3:a:autodesk:civil_3d:2026:*:*:*:*:*:*:*
Create a notification for this product.
   Autodesk Advance Steel Version: 2026   < 2026.1
    cpe:2.3:a:autodesk:advance_steel:2026:*:*:*:*:*:*:*
Create a notification for this product.
   Autodesk RealDWG Version: 2026   < 2026.0.2
    cpe:2.3:a:autodesk:realdwg:2026:*:*:*:*:*:*:*
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2025-5039",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2025-07-24T00:00:00+00:00",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2025-07-25T03:55:30.703Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "cpes": [
            "cpe:2.3:a:autodesk:autocad:2026:*:*:*:*:*:*:*"
          ],
          "defaultStatus": "unaffected",
          "product": "AutoCAD",
          "vendor": "Autodesk",
          "versions": [
            {
              "lessThan": "2026.1",
              "status": "affected",
              "version": "2026",
              "versionType": "custom"
            }
          ]
        },
        {
          "cpes": [
            "cpe:2.3:a:autodesk:autocad_lt:2026:*:*:*:*:*:*:*"
          ],
          "defaultStatus": "unaffected",
          "product": "AutoCAD LT",
          "vendor": "Autodesk",
          "versions": [
            {
              "lessThan": "2026.1",
              "status": "affected",
              "version": "2026",
              "versionType": "custom"
            }
          ]
        },
        {
          "cpes": [
            "cpe:2.3:a:autodesk:autocad_architecture:2026:*:*:*:*:*:*:*"
          ],
          "defaultStatus": "unaffected",
          "product": "AutoCAD Architecture",
          "vendor": "Autodesk",
          "versions": [
            {
              "lessThan": "2026.1",
              "status": "affected",
              "version": "2026",
              "versionType": "custom"
            }
          ]
        },
        {
          "cpes": [
            "cpe:2.3:a:autodesk:autocad_electrical:2026:*:*:*:*:*:*:*"
          ],
          "defaultStatus": "unaffected",
          "product": "AutoCAD Electrical",
          "vendor": "Autodesk",
          "versions": [
            {
              "lessThan": "2026.1",
              "status": "affected",
              "version": "2026",
              "versionType": "custom"
            }
          ]
        },
        {
          "cpes": [
            "cpe:2.3:a:autodesk:autocad_mechanical:2026:*:*:*:*:*:*:*"
          ],
          "defaultStatus": "unaffected",
          "product": "AutoCAD Mechanical",
          "vendor": "Autodesk",
          "versions": [
            {
              "lessThan": "2026.1",
              "status": "affected",
              "version": "2026",
              "versionType": "custom"
            }
          ]
        },
        {
          "cpes": [
            "cpe:2.3:a:autodesk:autocad_mep:2026:*:*:*:*:*:*:*"
          ],
          "defaultStatus": "unaffected",
          "product": "AutoCAD MEP",
          "vendor": "Autodesk",
          "versions": [
            {
              "lessThan": "2026.1",
              "status": "affected",
              "version": "2026",
              "versionType": "custom"
            }
          ]
        },
        {
          "cpes": [
            "cpe:2.3:a:autodesk:autocad_plant_3d:2026:*:*:*:*:*:*:*"
          ],
          "defaultStatus": "unaffected",
          "product": "AutoCAD Plant 3D",
          "vendor": "Autodesk",
          "versions": [
            {
              "lessThan": "2026.1",
              "status": "affected",
              "version": "2026",
              "versionType": "custom"
            }
          ]
        },
        {
          "cpes": [
            "cpe:2.3:a:autodesk:autocad_map_3d:2026:*:*:*:*:*:*:*"
          ],
          "defaultStatus": "unaffected",
          "product": "AutoCAD MAP 3D",
          "vendor": "Autodesk",
          "versions": [
            {
              "lessThan": "2026.1",
              "status": "affected",
              "version": "2026",
              "versionType": "custom"
            }
          ]
        },
        {
          "cpes": [
            "cpe:2.3:a:autodesk:civil_3d:2026:*:*:*:*:*:*:*"
          ],
          "defaultStatus": "unaffected",
          "product": "Civil 3D",
          "vendor": "Autodesk",
          "versions": [
            {
              "lessThan": "2026.1",
              "status": "affected",
              "version": "2026",
              "versionType": "custom"
            }
          ]
        },
        {
          "cpes": [
            "cpe:2.3:a:autodesk:advance_steel:2026:*:*:*:*:*:*:*"
          ],
          "defaultStatus": "unaffected",
          "product": "Advance Steel",
          "vendor": "Autodesk",
          "versions": [
            {
              "lessThan": "2026.1",
              "status": "affected",
              "version": "2026",
              "versionType": "custom"
            }
          ]
        },
        {
          "cpes": [
            "cpe:2.3:a:autodesk:realdwg:2026:*:*:*:*:*:*:*"
          ],
          "defaultStatus": "unaffected",
          "product": "RealDWG",
          "vendor": "Autodesk",
          "versions": [
            {
              "lessThan": "2026.0.2",
              "status": "affected",
              "version": "2026",
              "versionType": "custom"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "A maliciously crafted binary file, when present while loading files in certain Autodesk applications, could lead to execution of arbitrary code in the context of the current process due to an untrusted search path being utilized.\u003cbr\u003e"
            }
          ],
          "value": "A maliciously crafted binary file, when present while loading files in certain Autodesk applications, could lead to execution of arbitrary code in the context of the current process due to an untrusted search path being utilized."
        }
      ],
      "impacts": [
        {
          "capecId": "CAPEC-38",
          "descriptions": [
            {
              "lang": "en",
              "value": "CAPEC-38 Leveraging/Manipulating Configuration File Search Paths"
            }
          ]
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-426",
              "description": "CWE-426 Untrusted Search Path",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2025-08-19T13:17:42.116Z",
        "orgId": "7e40ea87-bc65-4944-9723-dd79dd760601",
        "shortName": "autodesk"
      },
      "references": [
        {
          "tags": [
            "patch"
          ],
          "url": "https://www.autodesk.com/products/autodesk-access/overview"
        },
        {
          "tags": [
            "vendor-advisory"
          ],
          "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0014"
        }
      ],
      "source": {
        "discovery": "EXTERNAL"
      },
      "title": "Privilege Ecalation due to Untrusted Search Path Vulnerability",
      "x_generator": {
        "engine": "Vulnogram 0.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "7e40ea87-bc65-4944-9723-dd79dd760601",
    "assignerShortName": "autodesk",
    "cveId": "CVE-2025-5039",
    "datePublished": "2025-07-24T17:11:14.714Z",
    "dateReserved": "2025-05-21T13:00:59.147Z",
    "dateUpdated": "2025-08-19T13:17:42.116Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1",
  "vulnerability-lookup:meta": {
    "nvd": "{\"cve\":{\"id\":\"CVE-2025-5039\",\"sourceIdentifier\":\"psirt@autodesk.com\",\"published\":\"2025-07-24T17:15:32.817\",\"lastModified\":\"2025-08-19T14:15:40.773\",\"vulnStatus\":\"Modified\",\"cveTags\":[],\"descriptions\":[{\"lang\":\"en\",\"value\":\"A maliciously crafted binary file, when present while loading files in certain Autodesk applications, could lead to execution of arbitrary code in the context of the current process due to an untrusted search path being utilized.\"},{\"lang\":\"es\",\"value\":\"Un archivo binario manipulado con fines malintencionados, cuando est\u00e1 presente durante la carga de archivos en ciertas aplicaciones de Autodesk, podr\u00eda provocar la ejecuci\u00f3n de c\u00f3digo arbitrario en el contexto del proceso actual debido al uso de una ruta de b\u00fasqueda no confiable.\"}],\"metrics\":{\"cvssMetricV31\":[{\"source\":\"psirt@autodesk.com\",\"type\":\"Secondary\",\"cvssData\":{\"version\":\"3.1\",\"vectorString\":\"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H\",\"baseScore\":7.8,\"baseSeverity\":\"HIGH\",\"attackVector\":\"LOCAL\",\"attackComplexity\":\"LOW\",\"privilegesRequired\":\"NONE\",\"userInteraction\":\"REQUIRED\",\"scope\":\"UNCHANGED\",\"confidentialityImpact\":\"HIGH\",\"integrityImpact\":\"HIGH\",\"availabilityImpact\":\"HIGH\"},\"exploitabilityScore\":1.8,\"impactScore\":5.9}]},\"weaknesses\":[{\"source\":\"psirt@autodesk.com\",\"type\":\"Secondary\",\"description\":[{\"lang\":\"en\",\"value\":\"CWE-426\"}]}],\"configurations\":[{\"nodes\":[{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:autodesk:infrastructure_parts_editor:*:*:*:*:*:*:*:*\",\"versionStartIncluding\":\"2026\",\"versionEndExcluding\":\"2026.0.2\",\"matchCriteriaId\":\"03EE8BC1-4EC3-49E3-9C1C-CFBD8C531ECD\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:autodesk:inventor:*:*:*:*:*:*:*:*\",\"versionStartIncluding\":\"2026\",\"versionEndExcluding\":\"2026.0.2\",\"matchCriteriaId\":\"EF7D5DEC-D172-49F2-89AE-9BFC5DFE98A6\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:autodesk:navisworks_manage:*:*:*:*:*:*:*:*\",\"versionStartIncluding\":\"2026\",\"versionEndExcluding\":\"2026.0.2\",\"matchCriteriaId\":\"9E916918-4CF5-4628-BD1B-C6FA94CBB353\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:autodesk:navisworks_simulate:*:*:*:*:*:*:*:*\",\"versionStartIncluding\":\"2026\",\"versionEndExcluding\":\"2026.0.2\",\"matchCriteriaId\":\"F5AB26D6-C349-48FB-9A09-C32C987904A8\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:autodesk:revit:*:*:*:*:*:*:*:*\",\"versionStartIncluding\":\"2026\",\"versionEndExcluding\":\"2026.0.2\",\"matchCriteriaId\":\"0B92B643-9C29-4604-8967-EB7A238120AB\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:autodesk:vault:*:*:*:*:*:*:*:*\",\"versionStartIncluding\":\"2026\",\"versionEndExcluding\":\"2026.0.2\",\"matchCriteriaId\":\"AAA7B4A5-345D-47E2-B295-0AF2BE88C19E\"}]}]}],\"references\":[{\"url\":\"https://www.autodesk.com/products/autodesk-access/overview\",\"source\":\"psirt@autodesk.com\"},{\"url\":\"https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0014\",\"source\":\"psirt@autodesk.com\",\"tags\":[\"Vendor Advisory\"]}]}}",
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2025-5039\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"total\"}], \"version\": \"2.0.3\", \"timestamp\": \"2025-07-24T19:21:55.468320Z\"}}}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2025-07-24T19:22:17.578Z\"}}], \"cna\": {\"title\": \"Privilege Ecalation due to Untrusted Search Path Vulnerability\", \"source\": {\"discovery\": \"EXTERNAL\"}, \"impacts\": [{\"capecId\": \"CAPEC-38\", \"descriptions\": [{\"lang\": \"en\", \"value\": \"CAPEC-38 Leveraging/Manipulating Configuration File Search Paths\"}]}], \"metrics\": [{\"format\": \"CVSS\", \"cvssV3_1\": {\"scope\": \"UNCHANGED\", \"version\": \"3.1\", \"baseScore\": 7.8, \"attackVector\": \"LOCAL\", \"baseSeverity\": \"HIGH\", \"vectorString\": \"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H\", \"integrityImpact\": \"HIGH\", \"userInteraction\": \"REQUIRED\", \"attackComplexity\": \"LOW\", \"availabilityImpact\": \"HIGH\", \"privilegesRequired\": \"NONE\", \"confidentialityImpact\": \"HIGH\"}, \"scenarios\": [{\"lang\": \"en\", \"value\": \"GENERAL\"}]}], \"affected\": [{\"cpes\": [\"cpe:2.3:a:autodesk:autocad:2026:*:*:*:*:*:*:*\"], \"vendor\": \"Autodesk\", \"product\": \"AutoCAD\", \"versions\": [{\"status\": \"affected\", \"version\": \"2026\", \"lessThan\": \"2026.1\", \"versionType\": \"custom\"}], \"defaultStatus\": \"unaffected\"}, {\"cpes\": [\"cpe:2.3:a:autodesk:autocad_lt:2026:*:*:*:*:*:*:*\"], \"vendor\": \"Autodesk\", \"product\": \"AutoCAD LT\", \"versions\": [{\"status\": \"affected\", \"version\": \"2026\", \"lessThan\": \"2026.1\", \"versionType\": \"custom\"}], \"defaultStatus\": \"unaffected\"}, {\"cpes\": [\"cpe:2.3:a:autodesk:autocad_architecture:2026:*:*:*:*:*:*:*\"], \"vendor\": \"Autodesk\", \"product\": \"AutoCAD Architecture\", \"versions\": [{\"status\": \"affected\", \"version\": \"2026\", \"lessThan\": \"2026.1\", \"versionType\": \"custom\"}], \"defaultStatus\": \"unaffected\"}, {\"cpes\": [\"cpe:2.3:a:autodesk:autocad_electrical:2026:*:*:*:*:*:*:*\"], \"vendor\": \"Autodesk\", \"product\": \"AutoCAD Electrical\", \"versions\": [{\"status\": \"affected\", \"version\": \"2026\", \"lessThan\": \"2026.1\", \"versionType\": \"custom\"}], \"defaultStatus\": \"unaffected\"}, {\"cpes\": [\"cpe:2.3:a:autodesk:autocad_mechanical:2026:*:*:*:*:*:*:*\"], \"vendor\": \"Autodesk\", \"product\": \"AutoCAD Mechanical\", \"versions\": [{\"status\": \"affected\", \"version\": \"2026\", \"lessThan\": \"2026.1\", \"versionType\": \"custom\"}], \"defaultStatus\": \"unaffected\"}, {\"cpes\": [\"cpe:2.3:a:autodesk:autocad_mep:2026:*:*:*:*:*:*:*\"], \"vendor\": \"Autodesk\", \"product\": \"AutoCAD MEP\", \"versions\": [{\"status\": \"affected\", \"version\": \"2026\", \"lessThan\": \"2026.1\", \"versionType\": \"custom\"}], \"defaultStatus\": \"unaffected\"}, {\"cpes\": [\"cpe:2.3:a:autodesk:autocad_plant_3d:2026:*:*:*:*:*:*:*\"], \"vendor\": \"Autodesk\", \"product\": \"AutoCAD Plant 3D\", \"versions\": [{\"status\": \"affected\", \"version\": \"2026\", \"lessThan\": \"2026.1\", \"versionType\": \"custom\"}], \"defaultStatus\": \"unaffected\"}, {\"cpes\": [\"cpe:2.3:a:autodesk:autocad_map_3d:2026:*:*:*:*:*:*:*\"], \"vendor\": \"Autodesk\", \"product\": \"AutoCAD MAP 3D\", \"versions\": [{\"status\": \"affected\", \"version\": \"2026\", \"lessThan\": \"2026.1\", \"versionType\": \"custom\"}], \"defaultStatus\": \"unaffected\"}, {\"cpes\": [\"cpe:2.3:a:autodesk:civil_3d:2026:*:*:*:*:*:*:*\"], \"vendor\": \"Autodesk\", \"product\": \"Civil 3D\", \"versions\": [{\"status\": \"affected\", \"version\": \"2026\", \"lessThan\": \"2026.1\", \"versionType\": \"custom\"}], \"defaultStatus\": \"unaffected\"}, {\"cpes\": [\"cpe:2.3:a:autodesk:advance_steel:2026:*:*:*:*:*:*:*\"], \"vendor\": \"Autodesk\", \"product\": \"Advance Steel\", \"versions\": [{\"status\": \"affected\", \"version\": \"2026\", \"lessThan\": \"2026.1\", \"versionType\": \"custom\"}], \"defaultStatus\": \"unaffected\"}, {\"cpes\": [\"cpe:2.3:a:autodesk:realdwg:2026:*:*:*:*:*:*:*\"], \"vendor\": \"Autodesk\", \"product\": \"RealDWG\", \"versions\": [{\"status\": \"affected\", \"version\": \"2026\", \"lessThan\": \"2026.0.2\", \"versionType\": \"custom\"}], \"defaultStatus\": \"unaffected\"}], \"references\": [{\"url\": \"https://www.autodesk.com/products/autodesk-access/overview\", \"tags\": [\"patch\"]}, {\"url\": \"https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0014\", \"tags\": [\"vendor-advisory\"]}], \"x_generator\": {\"engine\": \"Vulnogram 0.2.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"A maliciously crafted binary file, when present while loading files in certain Autodesk applications, could lead to execution of arbitrary code in the context of the current process due to an untrusted search path being utilized.\", \"supportingMedia\": [{\"type\": \"text/html\", \"value\": \"A maliciously crafted binary file, when present while loading files in certain Autodesk applications, could lead to execution of arbitrary code in the context of the current process due to an untrusted search path being utilized.\u003cbr\u003e\", \"base64\": false}]}], \"problemTypes\": [{\"descriptions\": [{\"lang\": \"en\", \"type\": \"CWE\", \"cweId\": \"CWE-426\", \"description\": \"CWE-426 Untrusted Search Path\"}]}], \"providerMetadata\": {\"orgId\": \"7e40ea87-bc65-4944-9723-dd79dd760601\", \"shortName\": \"autodesk\", \"dateUpdated\": \"2025-08-19T13:17:42.116Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2025-5039\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2025-08-19T13:17:42.116Z\", \"dateReserved\": \"2025-05-21T13:00:59.147Z\", \"assignerOrgId\": \"7e40ea87-bc65-4944-9723-dd79dd760601\", \"datePublished\": \"2025-07-24T17:11:14.714Z\", \"assignerShortName\": \"autodesk\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…