7.8
/ 10
HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Description
A maliciously crafted file, when executed on the victim's machine, can lead to privilege escalation to NT AUTHORITY/SYSTEM due to an insufficient validation of loaded binaries. An attacker with local and low-privilege access could exploit this to execute code as SYSTEM.
Basic Information
ID
CVE-2025-10885
Source
autodesk
Published
Nov 6, 2025 at 17:01
Modified
Nov 6, 2025 at 17:58
Affected Product
Vendor
Autodesk
Product
Installer
Version
2.18
Affected Versions
Autodesk Installer 2.18