Heap-based buffer overflow in Autodesk products - CVE-2025-8894

 

Heap-based buffer overflow in Autodesk products - CVE-2025-8894

Published: September 19, 2025


Vulnerability identifier: #VU115965
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-8894
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error. A remote attacker can trick the victim into opening a specially crafted PDF file, trigger a heap-based buffer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

AutoCAD LT
AutoCAD Map 3D
AutoCAD Architecture
AutoCAD Plant 3D
Autodesk Civil 3D
AutoCAD Electrical
AutoCAD MEP
Advance Steel
AutoCAD Mechanical
Revit
Autodesk AutoCAD

How to mitigate CVE-2025-8894

Install updates from vendor's website.

AutoCAD LT - addressed in versions 2024.1.8, 2025.1.3, 2026.1
AutoCAD Map 3D - addressed in versions 2024.1.8, 2025.1.3, 2026.1
Autodesk AutoCAD - addressed in versions 2024.1.8, 2025.1.3, 2026.1
AutoCAD Architecture - addressed in versions 2024.1.8, 2025.1.3, 2026.1
AutoCAD Plant 3D - addressed in versions 2024.1.8, 2025.1.3, 2026.1
Autodesk Civil 3D - addressed in versions 2024.1.8, 2025.1.3, 2026.1
AutoCAD Electrical - addressed in versions 2024.1.8, 2025.1.3, 2026.1
AutoCAD MEP - addressed in versions 2024.1.8, 2025.1.3, 2026.1
Advance Steel - addressed in versions 2024.1.8, 2025.1.3, 2026.1
AutoCAD Mechanical - addressed in versions 2024.1.8, 2025.1.3, 2026.1
Revit - addressed in versions 2025.4.3, 2026.3

External References

Related Security Bulletins