CVE-2025-10885: Autodesk Installer

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

A maliciously crafted file, when executed on the victim's machine, can lead to privilege escalation to NT AUTHORITY/SYSTEM due to an insufficient validation of loaded binaries. An attacker with local and low-privilege access could exploit this to execute code as SYSTEM.

Affected products

  • Autodesk Installer: before 2.19 (fixed in 2.19)

Published 2025-11-06. Last modified 2026-10-07.