7.8
CVE-2025-5039
- EPSS 0.05%
- Veröffentlicht 24.07.2025 17:15:32
- Zuletzt bearbeitet 19.08.2025 14:15:40
- Quelle psirt@autodesk.com
- CVE-Watchlists
- Unerledigt
A maliciously crafted binary file, when present while loading files in certain Autodesk applications, could lead to execution of arbitrary code in the context of the current process due to an untrusted search path being utilized.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Autodesk ≫ Infrastructure Parts Editor Version >= 2026 < 2026.0.2
Autodesk ≫ Navisworks Manage Version >= 2026 < 2026.0.2
Autodesk ≫ Navisworks Simulate Version >= 2026 < 2026.0.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.05% | 0.139 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| psirt@autodesk.com | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
CWE-426 Untrusted Search Path
The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.