Input Validation Flaw in Autodesk Installer Affecting System Stability
CVE-2026-14479

5.5MEDIUM

Key Information:

Vendor

Autodesk

Status
Vendor
CVE Published:
12 August 2026

What is CVE-2026-14479?

The Autodesk Installer contains an input validation flaw in its IPC frame parser. When processing specially crafted input, the parser may not correctly validate the positional attributes specified, leading to potential out-of-bounds substring operations. Exploitation of this vulnerability could allow a malicious actor to induce an unexpected termination of the NT AUTHORITY\SYSTEM service, subsequently resulting in a denial-of-service condition for the affected system.

Affected Version(s)

Installer 2.22.0 < 2.23.0

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.