CVE-2026-14478
Received Received - Intake

Local Privilege Escalation via Named Pipe Manipulation

Vulnerability report for CVE-2026-14478, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-12

Last updated on: 2026-08-12

Assigner: Autodesk

Description

A maliciously created executable, when executed on the victim's machine, may allow a local low-privileged attacker to inject unauthenticated IPC messages into named pipes, modify pipe permissions or ownership, and potentially impact confidentiality, integrity, and availability.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-12
Last Modified
2026-08-12
Generated
2026-08-12
AI Q&A
2026-08-12
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
autodesk adodis *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-732 The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves a malicious executable that, when run on a victim's system, allows a low-privileged local attacker to send unauthenticated IPC messages through named pipes. The attacker could also alter pipe permissions or ownership, potentially leading to unauthorized access or system manipulation.

Detection Guidance

Detecting this vulnerability requires monitoring for unauthorized IPC message injection or pipe permission changes. Check named pipes for unexpected modifications using system tools like 'sc query' or 'Get-NamedPipe' in PowerShell. Inspect process execution logs for suspicious executable launches.

Impact Analysis

The impact includes potential breaches of confidentiality, integrity, and availability of the affected system. An attacker could exploit this to gain unauthorized access, modify system behavior, or disrupt services, depending on the system's configuration and the attacker's goals.

Compliance Impact

This vulnerability could lead to unauthorized data access or modification, violating confidentiality and integrity requirements in GDPR and HIPAA. Organizations may face compliance violations, legal penalties, and reputational damage if exploited.

Mitigation Strategies

Immediately restrict execution of untrusted executables, especially AdODIS-installer.exe. Monitor and audit named pipe permissions regularly. Apply least privilege principles to limit local attacker capabilities. Disable unnecessary named pipes if possible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-14478. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart