A maliciously crafted DGN file, when linked or imported into Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
| Software | From | Fixed in |
|---|---|---|
| autodesk / advance_steel | 2026 | 2026.x |
| autodesk / autocad | 2026 | 2026.x |
| autodesk / autocad_architecture | 2026 | 2026.x |
| autodesk / autocad_electrical | 2026 | 2026.x |
| autodesk / autocad_lt | 2026 | 2026.x |
| autodesk / autocad_map_3d | 2026 | 2026.x |
| autodesk / autocad_mechanical | 2026 | 2026.x |
| autodesk / autocad_mep | 2026 | 2026.x |
| autodesk / autocad_plant_3d | 2026 | 2026.x |
| autodesk / civil_3d | 2026 | 2026.x |