CVE-2025-10885: Autodesk Installer
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
A maliciously crafted file, when executed on the victim's machine, can lead to privilege escalation to NT AUTHORITY/SYSTEM due to an insufficient validation of loaded binaries. An attacker with local and low-privilege access could exploit this to execute code as SYSTEM.
Affected products
- Autodesk Installer: before 2.19 (fixed in 2.19)
Published 2025-11-06. Last modified 2026-10-07.