Autodesk
Autodesk Revit: vulnerabilidades y CVE
Autodesk Revit tiene 40 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE40
Últimos 12 meses6
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-8325 | Alta (7.8) | 0.19% | — | 6 ago 2026 | A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or… |
| CVE-2026-1289 | Alta (7.8) | 0.19% | — | 6 ago 2026 | A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, disclose sensitive data, or… |
| CVE-2026-11803 | Alta (7.8) | 0.19% | — | 6 ago 2026 | A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or… |
| CVE-2026-7406 | Alta (7.8) | 0.19% | — | 6 ago 2026 | A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the… |
| CVE-2026-7405 | Media (5.5) | 0.16% | — | 6 ago 2026 | A maliciously crafted TIF file, when parsed through certain Autodesk products during image import, can cause an Out-of-Bounds Read in the image handling library. A malicious actor can leverage this vulnerability to… |
| CVE-2026-1288 | Media (5.5) | 0.12% | — | 17 jun 2026 | A maliciously crafted RFA file, when converted to FormIt via “Convert RFA to FormIt” in Autodesk Revit, can force a NULL Pointer Dereference vulnerability. Successful exploitation may cause the application to crash,… |
| CVE-2025-8354 | Alta (7.8) | 0.18% | — | 23 sept 2025 | A maliciously crafted RFA file, when parsed through Autodesk Revit, can force a Type Confusion vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute… |
| CVE-2025-8894 | Alta (7.8) | 0.17% | — | 16 sept 2025 | A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or… |
| CVE-2025-8893 | Alta (7.8) | 0.17% | — | 16 sept 2025 | A maliciously crafted PDF file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption,… |
| CVE-2025-5039 | Alta (7.8) | 0.18% | — | 24 jul 2025 | A maliciously crafted binary file, when present while loading files in certain Autodesk applications, could lead to execution of arbitrary code in the context of the current process due to an untrusted search path being… |
| CVE-2025-5042 | Alta (7.8) | 0.16% | — | 22 jul 2025 | A maliciously crafted RFA file, when parsed through Autodesk Revit, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute… |
| CVE-2025-5040 | Alta (7.8) | 0.18% | — | 10 jul 2025 | A maliciously crafted RTE file, when parsed through Autodesk Revit, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute… |
| CVE-2025-5037 | Alta (7.8) | 0.36% | — | 10 jul 2025 | A maliciously crafted RFA, RTE, or RVT file, when parsed through Autodesk Revit, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of… |
| CVE-2025-5036 | Alta (7.8) | 0.20% | — | 2 jun 2025 | A maliciously crafted RFA file, when linked or imported into Autodesk Revit, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute… |
| CVE-2025-2497 | Alta (7.8) | 0.33% | — | 15 abr 2025 | A maliciously crafted DWG file, when parsed through Autodesk Revit, can cause a Stack-Based Buffer Overflow vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of… |
| CVE-2025-1656 | Alta (7.8) | 0.27% | — | 15 abr 2025 | A maliciously crafted PDF file, when linked or imported into Autodesk applications, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data,… |
| CVE-2025-1277 | Alta (7.8) | 0.27% | — | 15 abr 2025 | A maliciously crafted PDF file, when parsed through Autodesk applications, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the… |
| CVE-2025-1276 | Alta (7.8) | 0.29% | — | 15 abr 2025 | A maliciously crafted DWG file, when parsed through certain Autodesk applications, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data… |
| CVE-2025-1275 | Alta (7.8) | 0.38% | — | 15 abr 2025 | A maliciously crafted JPG file, when linked or imported into certain Autodesk applications, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read… |
| CVE-2025-1274 | Alta (7.8) | 0.23% | — | 15 abr 2025 | A maliciously crafted RCS file, when parsed through Autodesk Revit, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute… |
| CVE-2025-1273 | Alta (7.8) | 0.21% | — | 15 abr 2025 | A maliciously crafted PDF file, when linked or imported into Autodesk applications, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data,… |
| CVE-2024-11608 | Alta (7.8) | 0.19% | — | 9 dic 2024 | A maliciously crafted SKP file, when linked or imported into Autodesk Revit, can be used to cause a Heap-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or… |
| CVE-2024-11454 | Alta (7.8) | 0.19% | — | 9 dic 2024 | A maliciously crafted DLL file, when placed in the same directory as an RVT file could be loaded by Autodesk Revit, and execute arbitrary code in the context of the current process due to an untrusted search patch being… |
| CVE-2024-11268 | Media (5.5) | 0.17% | — | 9 dic 2024 | A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Read. A malicious actor can leverage this vulnerability to cause a crash or could lead to an arbitrary memory leak. |
| CVE-2024-7994 | Alta (7.8) | 0.21% | — | 16 oct 2024 | A maliciously crafted RFA file, when parsed through Autodesk Revit, can force a Stack-Based Buffer Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary… |
| CVE-2024-7993 | Alta (7.8) | 0.19% | — | 16 oct 2024 | A maliciously crafted PDF file, when parsed through Autodesk Revit, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute… |
| CVE-2024-37008 | Alta (7.8) | 0.24% | — | 21 ago 2024 | A maliciously crafted DWG file, when parsed in Revit, can force a stack-based buffer overflow. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process. |
| CVE-2023-25002 | Alta (7.8) | 0.35% | — | 27 jun 2023 | A maliciously crafted SKP file in Autodesk products is used to trigger use-after-free vulnerability. Exploitation of this vulnerability may lead to code execution. |
| CVE-2023-29068 | Alta (7.8) | 0.24% | — | 27 jun 2023 | A maliciously crafted file consumed through pskernel.dll file could lead to memory corruption vulnerabilities. These vulnerabilities in conjunction with other vulnerabilities could lead to code execution in the context… |
| CVE-2023-25004 | Alta (7.8) | 0.24% | — | 27 jun 2023 | A maliciously crafted pskernel.dll file in Autodesk products is used to trigger integer overflow vulnerabilities. Exploitation of these vulnerabilities may lead to code execution. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.