Memory Corruption Vulnerability in Autodesk Revit
CVE-2025-5037

7.8HIGH

Key Information:

Vendor

Autodesk

Status
Vendor
CVE Published:
10 July 2025

What is CVE-2025-5037?

A vulnerability exists in Autodesk Revit where a specially crafted RFA file can lead to memory corruption. An attacker could exploit this flaw to execute arbitrary code within the context of the currently running process. This vulnerability emphasizes the importance of careful file handling and awareness of file integrity in Autodesk Revit to prevent exploitation and ensure the security of user data.

Affected Version(s)

Revit 2026 < 2026.2

Revit 2025 < 2025.4.2

Revit 2024 < 2024.3.3

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.