logo

Crafting a Full Exploit RCE from a Crash in Autodesk Revit RFA File Parsing

ID: 37cd605d-bc91-56b9-8cb1-0cdc73a00efa

STIX ID: report--37cd605d-bc91-56b9-8cb1-0cdc73a00efa

Feed Name: Zero Day Initiative (ZDI) Blog

Threat Score
65/100

Date Published: 2025-10-08

Date Updated: 2026-05-01

Author: Simon Zuckerbraun

...
...

This report documents an exploit development technique that achieves a 64-bit stack pivot and ROP execution on Windows 10/11 by abusing a destructor loop and GDI calls in a program: the author uses a sequence of gadgets (push rax; pop rbp; ret and leave) and a loop-based “weird machine” to transfer a heap-derived value into rsp, enabling a conventional ROP chain and arbitrary code execution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.