Vulnerability Details CVE-2026-14479
A maliciously crafted input, when processed by the Autodesk Installer IPC frame parser, may trigger improper validation of an input-specified position or offset, resulting in an out-of-range substring operation. A malicious actor may leverage this vulnerability to cause the NT AUTHORITY\SYSTEM service to terminate unexpectedly, resulting in a denial-of-service condition.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 1.6%
CVSS Severity
CVSS v3 Score 5.5
Products affected by CVE-2026-14479
-
cpe:2.3:a:autodesk:installer:2.10.0.17
-
cpe:2.3:a:autodesk:installer:2.10.0.20
-
cpe:2.3:a:autodesk:installer:2.13
-
cpe:2.3:a:autodesk:installer:2.15
-
cpe:2.3:a:autodesk:installer:2.17
-
cpe:2.3:a:autodesk:installer:2.18
-
cpe:2.3:a:autodesk:installer:2.19
-
cpe:2.3:a:autodesk:installer:2.21