CVE-2025-1430
Published: 13 March 2025
Description
An adversary may rely upon a user opening a malicious file in order to gain execution.
Security Summary
CVE-2025-1430 is a memory corruption vulnerability (CWE-120, CWE-787) affecting Autodesk AutoCAD when parsing a maliciously crafted SLDPRT file. Published on 2025-03-13 with a CVSS v3.1 base score of 7.8 (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H), it allows a malicious actor to trigger the issue during file processing, potentially leading to arbitrary code execution in the context of the AutoCAD process.
The vulnerability requires local access to the target system with low attack complexity but demands user interaction, such as convincing a user to open the malicious SLDPRT file in AutoCAD. No privileges are needed beforehand. Successful exploitation enables the attacker to execute arbitrary code with the privileges of the current user running AutoCAD, potentially compromising the system through high impacts on confidentiality, integrity, and availability.
Autodesk has published security advisory ADSK-SA-2025-0001 addressing this issue, with updates available for AutoCAD and AutoCAD LT. Users can download the latest updates from Autodesk's support pages, such as those for AutoCAD 2022, via Autodesk Access.
Details
- CWE(s)
Affected Products
MITRE ATT&CK Enterprise Techniques
Why these techniques?
Memory corruption in AutoCAD SLDPRT parser enables RCE on file open, mapping directly to client-side exploitation (T1203) and user execution of malicious file (T1204.002).