CVE-2025-5039: Autodesk Infrastructure Parts Editor
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
A maliciously crafted binary file, when present while loading files in certain Autodesk applications, could lead to execution of arbitrary code in the context of the current process due to an untrusted search path being utilized.
Affected products
- Autodesk Infrastructure Parts Editor: from 2026, before 2026.0.2 (fixed in 2026.0.2)
- Autodesk Inventor: from 2026, before 2026.0.2 (fixed in 2026.0.2)
- Autodesk Navisworks Manage: from 2026, before 2026.0.2 (fixed in 2026.0.2)
- Autodesk Navisworks Simulate: from 2026, before 2026.0.2 (fixed in 2026.0.2)
- Autodesk Revit: from 2026, before 2026.0.2 (fixed in 2026.0.2)
- Autodesk Vault: from 2026, before 2026.0.2 (fixed in 2026.0.2)
Published 2025-07-24. Last modified 2026-06-17.