High severity7.8NVD Advisory· Published Jul 24, 2025· Updated Jun 17, 2026
CVE-2025-5039
CVE-2025-5039
Description
A maliciously crafted binary file, when present while loading files in certain Autodesk applications, could lead to execution of arbitrary code in the context of the current process due to an untrusted search path being utilized.
Affected products
18- cpe:2.3:a:autodesk:autocad_architecture:2026:*:*:*:*:*:*:*Range: 2026
- cpe:2.3:a:autodesk:autocad_electrical:2026:*:*:*:*:*:*:*Range: 2026
- cpe:2.3:a:autodesk:autocad_mechanical:2026:*:*:*:*:*:*:*Range: 2026
- cpe:2.3:a:autodesk:autocad_plant_3d:2026:*:*:*:*:*:*:*Range: 2026
- cpe:2.3:a:autodesk:infrastructure_parts_editor:*:*:*:*:*:*:*:*Range: >=2026,<2026.0.2
- cpe:2.3:a:autodesk:navisworks_manage:*:*:*:*:*:*:*:*Range: >=2026,<2026.0.2
- cpe:2.3:a:autodesk:navisworks_simulate:*:*:*:*:*:*:*:*Range: >=2026,<2026.0.2
- Autodesk/RealDWGv5cpe:2.3:a:autodesk:realdwg:2026:*:*:*:*:*:*:*Range: 2026
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.