PT-2023-3129 · Autodesk · Autodesk Fbx-Sdk

Published

2023-03-29

·

Updated

2023-09-26

·

CVE-2023-27909

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Autodesk FBX SDK versions 2020 or prior
Description The issue is related to an Out-Of-Bounds Write, which may lead to code execution or information disclosure through maliciously crafted FBX files.
Recommendations For versions 2020 or prior, update to a version later than 2020 to resolve the issue. As a temporary workaround, consider restricting the use of maliciously crafted FBX files until a patch is available. Avoid using the FBX SDK to parse untrusted FBX files until the issue is resolved.

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-03227
CVE-2023-27909
ZDI-23-1421

Affected Products

Autodesk Fbx-Sdk