A maliciously crafted binary file when downloaded could lead to escalation of privileges to NT AUTHORITY/SYSTEM due to an untrusted search path being utilized in the VRED Design application. Exploitation of this vulnerability may lead to code execution.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-48825 A maliciously crafted binary file when downloaded could lead to escalation of privileges to NT AUTHORITY/SYSTEM due to an untrusted search path being utilized in the VRED Design application. Exploitation of this vulnerability may lead to code execution.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 27 Aug 2025 03:45:00 +0900

Type Values Removed Values Added
First Time appeared Autodesk vred Design
CPEs cpe:2.3:a:autodesk:vred_design:2025:*:*:*:*:*:*:*
Vendors & Products Autodesk vred Design

Tue, 19 Aug 2025 06:30:00 +0900

Type Values Removed Values Added
References

Tue, 19 Aug 2025 05:30:00 +0900

Type Values Removed Values Added
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Wed, 30 Jul 2025 04:15:00 +0900

Type Values Removed Values Added
CPEs cpe:2.3:a:autodesk:vred:*:*:*:*:design:*:*:*

Wed, 06 Nov 2024 07:15:00 +0900

Type Values Removed Values Added
First Time appeared Autodesk
Autodesk vred
CPEs cpe:2.3:a:autodesk:vred:2025:*:*:*:*:*:*:*
Vendors & Products Autodesk
Autodesk vred
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 06 Nov 2024 05:15:00 +0900

Type Values Removed Values Added
Description A maliciously crafted binary file when downloaded could lead to escalation of privileges to NT AUTHORITY/SYSTEM due to an untrusted search path being utilized in the VRED Design application. Exploitation of this vulnerability may lead to code execution.
Title Autodesk VRED Design Privilege Escalation Vulnerability
Weaknesses CWE-426
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: autodesk

Published:

Updated: 2025-08-26T18:27:06.333Z

Reserved: 2024-08-19T21:37:11.389Z

Link: CVE-2024-7995

cve-icon Vulnrichment

Updated: 2024-11-05T21:45:30.553Z

cve-icon NVD

Status : Modified

Published: 2024-11-05T20:15:15.423

Modified: 2025-08-18T21:15:29.723

Link: CVE-2024-7995

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses