VYPR
Unrated severityNVD Advisory· Published Jul 24, 2025· Updated Feb 26, 2026

Privilege Ecalation due to Untrusted Search Path Vulnerability

CVE-2025-5039

Description

A maliciously crafted binary file, when present while loading files in certain Autodesk applications, could lead to execution of arbitrary code in the context of the current process due to an untrusted search path being utilized.

Affected products

11
  • Autodesk/Advance Steelv5
    cpe:2.3:a:autodesk:advance_steel:2026:*:*:*:*:*:*:*
    Range: 2026
  • cpe:2.3:a:autodesk:autocad:2026:*:*:*:*:*:*:*
    Range: 2026
  • Autodesk/AutoCAD Architecturev5
    cpe:2.3:a:autodesk:autocad_architecture:2026:*:*:*:*:*:*:*
    Range: 2026
  • Autodesk/AutoCAD Electricalv5
    cpe:2.3:a:autodesk:autocad_electrical:2026:*:*:*:*:*:*:*
    Range: 2026
  • Autodesk/AutoCAD LTv5
    cpe:2.3:a:autodesk:autocad_lt:2026:*:*:*:*:*:*:*
    Range: 2026
  • Autodesk/AutoCAD MAP 3Dv5
    cpe:2.3:a:autodesk:autocad_map_3d:2026:*:*:*:*:*:*:*
    Range: 2026
  • Autodesk/AutoCAD Mechanicalv5
    cpe:2.3:a:autodesk:autocad_mechanical:2026:*:*:*:*:*:*:*
    Range: 2026
  • Autodesk/AutoCAD MEPv5
    cpe:2.3:a:autodesk:autocad_mep:2026:*:*:*:*:*:*:*
    Range: 2026
  • Autodesk/AutoCAD Plant 3Dv5
    cpe:2.3:a:autodesk:autocad_plant_3d:2026:*:*:*:*:*:*:*
    Range: 2026
  • Autodesk/Civil 3Dv5
    cpe:2.3:a:autodesk:civil_3d:2026:*:*:*:*:*:*:*
    Range: 2026
  • Autodesk/RealDWGv5
    cpe:2.3:a:autodesk:realdwg:2026:*:*:*:*:*:*:*
    Range: 2026

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.