References https://nvd.nist.gov/vuln/detail/CVE-2025-5036 https://www.cve.org/CVERecord?id=CVE-2025-5036 https://www.cvedetails.com/cve/CVE-2025-5036/ https://www.autodesk.com/trust/security-advisories/adsk-sa-2025-0009 https://www.zerodayinitiative.com/advisories/ZDI-25-331/ https://www.ameeba.com/blog/cve-2025-5036-use-after-free-vulnerability-in-autodesk-revit-linked-with-malicious-rfa-files/ https://github.com/advisories/GHSA-rhfv-c52c-x747
Related VulnerabilitiesPoCafterlogic-path-disclosure: AfterLogic Aurora and WebMail Pro < 7.7.9 - Full Path DisclosurePoCCVE-2023-27624: WordPress Redirect After Login <= 0.1.9 - Admin Stored XSSCrafterCMS存在XSS漏洞(CVE-2023-4136)(CVE-2025-5047)Autodesk AutoCAD解析DGN文件未初始化变量漏洞(CVE-2025-5046)Autodesk AutoCAD DGN文件处理越界读漏洞PoCCVE-2021-26292: AfterLogic Aurora and WebMail Pro < 7.7.9 - Full Path DisclosurePoCCVE-2021-26294: AfterLogic Aurora and WebMail Pro < 7.7.9 - Information DisclosurePoCCVE-2023-4136: CrafterCMS Engine - Cross-Site ScriptingPoCafterpay-help-csp-bypass: Content-Security-Policy Bypass - Afterpay HelpPoCaftership-takeover: Aftership - Subdomain Takeover DetectionPoCCVE-2025-49844: Redis Lua Parser < 8.2.2 - Use After Free关于用友A++V8系列产品gl/XXX/getCancelData接口SQL注入漏洞及/pub/XXX/burnAfterReading任意文件读取漏洞的安全公告WordPress plugin MD Custom content after or before of post 跨站请求伪造漏洞