Untrusted search path in Autodesk products - CVE-2025-5039

 

Untrusted search path in Autodesk products - CVE-2025-5039

Published: July 28, 2025


Vulnerability identifier: #VU113358
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-5039
CWE-ID: CWE-426
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the system.

The vulnerability exists due to usage of an untrusted search path. A remote attacker can use a specially crafted binary file to execute arbitrary code on the target system.


Affected software

Infrastructure Parts Editor
Revit
Autodesk Inventor
Autodesk Navisworks Manage
Autodesk Navisworks Simulate
Autodesk Vault Basic Client

How to mitigate CVE-2025-5039

Install updates from vendor's website.

Infrastructure Parts Editor - update to 2026.0.2
Autodesk Inventor - update to 2026.0.2
Autodesk Navisworks Manage - update to 2026.0.2
Autodesk Navisworks Simulate - update to 2026.0.2
Revit - update to 2026.0.2
Autodesk Vault Basic Client - update to 2026.0.2

External References

Related Security Bulletins