CVE-2025-10886High· 7.8▾ TwilightA maliciously crafted MODEL file, when parsed through certain Autodesk products, can force a Memory corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 42.9 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
A maliciously crafted MODEL file, when parsed through certain Autodesk products, can force a Memory corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
shared_components < 2026.5Upgrade past the affected range:
shared_components 2026.5Connected by shared product, vendor, weakness, or advisory.
CVE-2025-10887High· 7.8A maliciously crafted MODEL file, when parsed through certain Autodesk products, can force a Memory corruption vulnerability
CVE-2025-10889High· 7.8A maliciously crafted CATPART file, when parsed through certain Autodesk products, can force a Memory corruption vulnerability
CVE-2025-9459High· 7.8A maliciously crafted SLDPRT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Read vulnerability
CVE-2025-9460High· 7.8A maliciously crafted SLDPRT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Read vulnerability
CVE-2025-9455High· 7.8A maliciously crafted CATPRODUCT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Read vulnerability
CVE-2025-9456High· 7.8A maliciously crafted SLDPRT file, when parsed through certain Autodesk products, can force a Memory corruption vulnerability