CVE-2024-11268: Autodesk Revit

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Read. A malicious actor can leverage this vulnerability to cause a crash or could lead to an arbitrary memory leak.

Affected products

  • Autodesk Revit: from 2024, before 2024.3.1 (fixed in 2024.3.1); from 2025, before 2025.4 (fixed in 2025.4)

Published 2024-12-09. Last modified 2026-06-17.