Untrusted search path in Autodesk products - CVE-2025-5039
Published: July 28, 2025
Vulnerability identifier: #VU113358
CSH Severity: High
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2025-5039
CWE-ID: CWE-426
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vendor: Autodesk
Affected software:
Infrastructure Parts Editor
Revit
Autodesk Inventor
Autodesk Navisworks Manage
Autodesk Navisworks Simulate
Autodesk Vault Basic Client
Infrastructure Parts Editor
Revit
Autodesk Inventor
Autodesk Navisworks Manage
Autodesk Navisworks Simulate
Autodesk Vault Basic Client
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary code on the system.
The vulnerability exists due to usage of an untrusted search path. A remote attacker can use a specially crafted binary file to execute arbitrary code on the target system.
How to mitigate CVE-2025-5039
Install updates from vendor's website.