<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>AutoCAD (&lt; 2027.1.0) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/autocad--2027.1.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 06 Aug 2026 23:29:49 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/autocad--2027.1.0/feed.xml" rel="self" type="application/rss+xml"/><item><title>Arbitrary Code Execution in Autodesk Revit via Malicious PDF</title><link>https://feed.craftedsignal.io/briefs/2026-08-revit-pdf-vulnerability/</link><pubDate>Thu, 06 Aug 2026 23:29:49 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-revit-pdf-vulnerability/</guid><description>Autodesk Revit contains an out-of-bounds read vulnerability in its PDF parsing engine that can be exploited for arbitrary code execution or information disclosure.</description><content:encoded><![CDATA[<p>Autodesk has disclosed a high-severity vulnerability (CVE-2026-11803) affecting multiple versions of Autodesk Revit. The issue is rooted in an out-of-bounds read vulnerability occurring during the parsing of maliciously crafted PDF files. Successful exploitation requires user interaction, where an attacker must entice a victim to open a specially crafted PDF document within the Revit application. If successful, the vulnerability may allow a remote attacker to trigger an application crash, access sensitive process memory, or achieve arbitrary code execution within the context of the user running the Revit process. Organizations using Revit 2026 and 2027 should prioritize patching to the recommended versions to remediate the flaw.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2026-11803 allows for potential full system compromise within the security context of the user executing the Revit process. This could lead to the exfiltration of sensitive design data, unauthorized access to internal resources, or further lateral movement within the network. Users in the engineering, architecture, and construction sectors are primary targets due to the industry-specific nature of the software.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Apply security updates immediately for Autodesk Revit 2026 and 2027 to the versions specified in the Autodesk security advisory ADSK-SA-2026-0011.</li>
<li>Advise end-users to exercise caution when handling unsolicited PDF files, especially those sent to recipients who utilize Revit for design workflows.</li>
<li>Monitor endpoint process behavior for unexpected child processes spawned by Revit.exe, as this may indicate an attempt to gain code execution after an initial crash or memory read.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>cve</category><category>office-application</category></item></channel></rss>