7.8
CVE-2026-7406
- EPSS 0.13%
- Veröffentlicht 06.08.2026 22:18:32
- Zuletzt bearbeitet 07.08.2026 19:18:54
- CVE-Watchlists
- Unerledigt
BMP File Parsing Untrusted Pointer Dereference in certain Autodesk products
A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerAutodesk
≫
Produkt
Revit
Default Statusunaffected
Version
2027.0.0
Version <
2027.1.0
Status
affected
Version
2026.0.0
Version <
2026.5.0
Status
affected
Version
2024.0.0
Version <
2024.3.5
Status
affected
HerstellerAutodesk
≫
Produkt
AutoCAD
Default Statusunaffected
Version
2027.0.0
Version <
2027.1.0
Status
affected
Version
2026.0.0
Version <
2026.1.2
Status
affected
HerstellerAutodesk
≫
Produkt
AutoCAD LT
Default Statusunaffected
Version
2027.0.0
Version <
2027.1.0
Status
affected
Version
2026.0.0
Version <
2026.1.2
Status
affected
HerstellerAutodesk
≫
Produkt
DWG TrueView
Default Statusunaffected
Version
2027.0.0
Version <
2027.1.0
Status
affected
Version
2026.0.0
Version <
2026.1.2
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.13% | 0.033 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| Autodesk | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
CWE-822 Untrusted Pointer Dereference
The product obtains a value from an untrusted source, converts this value to a pointer, and dereferences the resulting pointer.
https://www.autodesk.com/products/autodesk-access/overview
https://www.autodesk.com/trust/security-advisories/adsk-sa-2026-0012