CVE-2025-1649
Published: 13 March 2025
Description
An adversary may rely upon a user opening a malicious file in order to gain execution.
Security Summary
CVE-2025-1649 is an uninitialized variable vulnerability (CWE-457, CWE-908) affecting Autodesk AutoCAD. The issue arises when AutoCAD parses a maliciously crafted CATPRODUCT file, which can trigger the flaw. Published on 2025-03-13, it has a CVSS v3.1 base score of 7.8 (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
A local attacker can exploit this vulnerability by convincing a user to open a specially crafted CATPRODUCT file in AutoCAD, requiring no privileges but relying on user interaction. Successful exploitation allows the attacker to cause a denial-of-service condition via application crash, read sensitive data from memory, or execute arbitrary code within the context of the AutoCAD process.
Autodesk has published security advisory ADSK-SA-2025-0001 addressing this issue. Mitigation involves applying the latest updates for AutoCAD, available through Autodesk Access or specific download pages for versions such as AutoCAD and AutoCAD LT 2022.
Details
- CWE(s)
Affected Products
MITRE ATT&CK Enterprise Techniques
Why these techniques?
The vulnerability is a client-side uninitialized variable flaw in AutoCAD triggered by parsing a malicious CATPRODUCT file, directly enabling exploitation for client execution (T1203) via user opening of a malicious file (T1204.002) leading to RCE, memory disclosure, or DoS.