Out-of-bounds write in Autodesk products - CVE-2025-8893

 

Out-of-bounds write in Autodesk products - CVE-2025-8893

Published: September 19, 2025


Vulnerability identifier: #VU115964
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-8893
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a boundary error when processing untrusted input. A remote attacker can create a specially crafted PDF file, trick the victim into opening it using the affected software, trigger an out-of-bounds write and execute arbitrary code on the target system.


Affected software

AutoCAD LT
AutoCAD Map 3D
AutoCAD Architecture
AutoCAD Plant 3D
Autodesk Civil 3D
AutoCAD Electrical
AutoCAD MEP
Advance Steel
AutoCAD Mechanical
Revit
Autodesk AutoCAD

How to mitigate CVE-2025-8893

Install updates from vendor's website.

AutoCAD LT - addressed in versions 2024.1.8, 2025.1.3, 2026.1
AutoCAD Map 3D - addressed in versions 2024.1.8, 2025.1.3, 2026.1
Autodesk AutoCAD - addressed in versions 2024.1.8, 2025.1.3, 2026.1
AutoCAD Architecture - addressed in versions 2024.1.8, 2025.1.3, 2026.1
AutoCAD Plant 3D - addressed in versions 2024.1.8, 2025.1.3, 2026.1
Autodesk Civil 3D - addressed in versions 2024.1.8, 2025.1.3, 2026.1
AutoCAD Electrical - addressed in versions 2024.1.8, 2025.1.3, 2026.1
AutoCAD MEP - addressed in versions 2024.1.8, 2025.1.3, 2026.1
Advance Steel - addressed in versions 2024.1.8, 2025.1.3, 2026.1
AutoCAD Mechanical - addressed in versions 2024.1.8, 2025.1.3, 2026.1
Revit - addressed in versions 2025.4.3, 2026.3

External References

Related Security Bulletins