VYPR
High severity7.8NVD Advisory· Published Jun 27, 2023· Updated Jun 17, 2026

CVE-2023-25002

CVE-2023-25002

Description

A maliciously crafted SKP file in Autodesk products is used to trigger use-after-free vulnerability. Exploitation of this vulnerability may lead to code execution.

Affected products

9
  • Autodesk/3ds Max2 versions
    cpe:2.3:a:autodesk:3ds_max:2022:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:autodesk:3ds_max:2022:*:*:*:*:*:*:*
    • cpe:2.3:a:autodesk:3ds_max:2023:*:*:*:*:*:*:*
  • cpe:2.3:a:autodesk:navisworks:2022:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:autodesk:navisworks:2022:*:*:*:*:*:*:*
    • cpe:2.3:a:autodesk:navisworks:2023:*:*:*:*:*:*:*
  • Autodesk/Revit2 versions
    cpe:2.3:a:autodesk:revit:2022:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:autodesk:revit:2022:*:*:*:*:*:*:*
    • cpe:2.3:a:autodesk:revit:2023:*:*:*:*:*:*:*
  • cpe:2.3:a:autodesk:vred:2023:*:*:*:*:*:*:*
  • Autodesk/Autodesk productsdescription

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.