A maliciously crafted TIF file, when parsed through certain Autodesk products during image import, can cause an Out-of-Bounds Read in the image handling library. A malicious actor can leverage this vulnerability to cause a denial of service
History

Fri, 07 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Autodesk dwg Trueview
CPEs cpe:2.3:a:autodesk:autocad:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_lt:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:dwg_trueview:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:dwg_trueview:2027:*:*:*:*:*:*:*
Vendors & Products Autodesk dwg Trueview

Fri, 07 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 06 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Description A maliciously crafted TIF file, when parsed through certain Autodesk products during image import, can cause an Out-of-Bounds Read in the image handling library. A malicious actor can leverage this vulnerability to cause a denial of service
Title TIF File Parsing Out-of-Bounds Read in certain Autodesk products
First Time appeared Autodesk
Autodesk autocad
Autodesk autocad Lt
Autodesk revit
Weaknesses CWE-125
CPEs cpe:2.3:a:autodesk:autocad:2027:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autocad_lt:2027:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:revit:2024:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:revit:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:revit:2027:*:*:*:*:*:*:*
Vendors & Products Autodesk
Autodesk autocad
Autodesk autocad Lt
Autodesk revit
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: autodesk

Published: 2026-08-06T16:17:54.589Z

Updated: 2026-08-07T18:30:02.441Z

Reserved: 2026-04-29T13:03:48.953Z

Link: CVE-2026-7405

cve-icon Vulnrichment

Updated: 2026-08-07T17:22:43.911Z

cve-icon NVD

No data.

cve-icon Redhat

No data.