CVE-2023-25005: Autodesk Infraworks

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

A maliciously crafted DLL file can be forced to read beyond allocated boundaries in Autodesk InfraWorks 2023, and 2021 when parsing the DLL files could lead to a resource injection vulnerability.

Affected products

  • Autodesk Infraworks: from 2021.0, before 2021.2 (fixed in 2021.2); from 2023.0, before 2023.1 (fixed in 2023.1); version 2021.2 only; version 2023.1 only

Published 2023-05-12. Last modified 2026-06-17.