CVE-2025-10889
HIGHDescription
A maliciously crafted CATPART file, when parsed through certain Autodesk products, can force a Memory corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
Is your site exposed to CVE-2025-10889?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| autodesk | shared_components |
| autodesk | 3ds_max |
| autodesk | advance_steel |
| autodesk | autocad |
| autodesk | autocad_architecture |
| autodesk | autocad_electrical |
| autodesk | autocad_map_3d |
| autodesk | autocad_mechanical |
| autodesk | autocad_mep |
| autodesk | autocad_plant_3d |
| autodesk | civil_3d |
| autodesk | infraworks |
| autodesk | inventor |
| autodesk | revit |
| autodesk | revit_lt |
| autodesk | vault |
References
Advisories & Patches
Other References
Frequently Asked Questions
What is CVE-2025-10889? +
How severe is CVE-2025-10889? +
What products are affected by CVE-2025-10889? +
How do I check if I'm vulnerable to CVE-2025-10889? +
Related Vulnerabilities
zlib is a Ruby interface for the zlib compression/decompression library. Versions 3.0.0 and below, 3.1.0, 3.1.1, 3.2.0 and 3.2.1 contain …
A denial-of-service issue exists in 5380/5480/5580 controllers boot firmware lower than version 1.072. This vulnerability could potentially allow a malicious …
A denial-of-service issue exists in 5380/5480/5580 controllers. This vulnerability could potentially allow a malicious user to write invalid file data …
A denial-of-service issue exists in 5370/5570 controllers. This vulnerability could potentially allow a remote user to load an invalid project, …
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Newtec NTC2218, NTC2250, NTC2299 on Linux, PowerPC, ARM …
An unauthenticated attacker on the WAN interface, with the ability to intercept Dynamic DNS (DDNS) traffic between DDNS services and …