Shared Components vulnerability

A maliciously crafted CATPRODUCT file, when parsed through certain Autodesk products, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

Published 15 Dec 2025Updated 17 Sep 20262 sources
CVSS 7.8

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.