CVE-2026-7406 - BMP File Parsing Untrusted Pointer Dereference in Autodesk Products
CVE-2026-7406 - BMP File Parsing Untrusted Pointer Dereference in Autodesk Products
A maliciously crafted BMP file, when parsed through certain Autodesk products, can force an Untrusted Pointer Dereference vulnerability, tracked as CVE-2026-7406. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process. This vulnerability was published on August 6, 2026, and is not remotely exploitable.
Affected Products
The following Autodesk products are affected by CVE-2026-7406:
- AutoCAD
- AutoCAD LT
- Revit
Severity Rating
The Common Vulnerability Scoring System (CVSS) rates this vulnerability with a HIGH severity score of 7.8, with an exploitability score of 1.8 and an impact score of 5.9.
Mitigation
To mitigate this vulnerability, users should update Autodesk products to the latest version to fix the untrusted pointer dereference vulnerability. Additionally, users are advised to avoid opening untrusted BMP files.
For further information, the official Autodesk security advisory can be found at: Autodesk Security Advisory.
To read the complete article see: Read full article