CVE-2022-25788High· 7.8▾ TwilightA maliciously crafted JT file in Autodesk AutoCAD 2022 may be used to write beyond the allocated buffer while parsing JT files. This vulnerability can be exploited to execute arbitrary code.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 42.9 · likelihood 0.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.6%
A maliciously crafted JT file in Autodesk AutoCAD 2022 may be used to write beyond the allocated buffer while parsing JT files. This vulnerability can be exploited to execute arbitrary code.
advance_steel >= 2022, < 2022.1.2autocad >= 2022, < 2022.1.2autocad >= 2022, < 2022.2.2autocad_architecture >= 2022, < 2022.1.2autocad_electrical >= 2022, < 2022.1.2autocad_lt >= 2022, < 2022.1.2autocad_lt >= 2022, < 2022.2.2autocad_map_3d >= 2022, < 2022.1.2autocad_mechanical >= 2022, < 2022.1.2autocad_mep >= 2022, < 2022.1.2autocad_plant_3d >= 2022, < 2022.1.2civil_3d >= 2022, < 2022.1.2inventor >= 2022, < 2022.2Upgrade past the affected range:
advance_steel 2022.1.2autocad 2022.2.2autocad_architecture 2022.1.2autocad_electrical 2022.1.2autocad_lt 2022.2.2autocad_map_3d 2022.1.2autocad_mechanical 2022.1.2autocad_mep 2022.1.2autocad_plant_3d 2022.1.2civil_3d 2022.1.2inventor 2022.2Connected by shared product, vendor, weakness, or advisory.
CVE-2021-40158High· 7.8A maliciously crafted JT file in Autodesk Inventor 2022, 2021, 2020, 2019 and AutoCAD 2022 may be forced to read beyond allocated boundaries when parsing the JT file
CVE-2021-40159High· 7.8An Information Disclosure vulnerability for JT files in Autodesk Inventor 2022, 2021, 2020, 2019 in conjunction with other vulnerabilities may lead to code execution through maliciously crafted JT files in the context of the current proc…
CVE-2022-27867High· 7.8A maliciously crafted JT file in Autodesk AutoCAD 2022, 2021, 2020, 2019 can be used to trigger use-after-free vulnerability
CVE-2025-9456High· 7.8A maliciously crafted SLDPRT file, when parsed through certain Autodesk products, can force a Memory corruption vulnerability
CVE-2025-9452High· 7.8A maliciously crafted SLDPRT file, when parsed through certain Autodesk products, can force a Memory corruption vulnerability
CVE-2025-9458High· 7.8A maliciously crafted PRT file, when parsed through certain Autodesk products, can force a Memory Corruption vulnerability