A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HAutodesk Revit
APPAutodesk2024 – 2024.3.6 (excl.)2025 – 2025.4.6 (excl.)2026 – 2026.5 (excl.)2027 – 2027.2 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEDoSMemory
CWE
Related vulnerabilities
CVE-2026-8325HIGH7.8PL ✓same product
Out-of-Bounds Write w Autodesk Revit podczas parsowania pliku PDF
CVE-2026-7406HIGH7.8PL ✓same product
RCE poprzez złośliwy plik BMP w produktach Autodesk (Untrusted Pointer Dereference)
CVE-2026-1289HIGH7.8PL ✓same product
Use-After-Free w Autodesk Revit przy parsowaniu pliku PDF
CVE-2026-0875HIGH7.8same product
A maliciously crafted MODEL file, when parsed through certain Autodesk products, can force an Out-of-Bounds Wr...
CVE-2026-0874HIGH7.8same product
A maliciously crafted CATPART file, when parsed through certain Autodesk products, can force an Out-of-Bounds ...