PT-2024-19689 · Autodesk · Autodesk Fbx Review
Published
2024-03-17
·
Updated
2024-08-27
·
CVE-2024-23139
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Autodesk FBX Review versions 1.5.3.0 and prior
Description
A maliciously crafted ABC file, when parsed through Autodesk FBX, may force an Out-of-Bounds Write issue. This can be leveraged to cause a crash, data corruption, or execute arbitrary code in the context of the current process. The issue is related to the parsing of ActionScript Byte Code “ABC” files, which are created by the Flash compiler and contain executable code. This issue, in conjunction with other issues, could lead to code execution in the context of the current process.
Recommendations
For Autodesk FBX Review versions 1.5.3.0 and prior, consider disabling the parsing of ABC files until a patch is available. Restrict access to the vulnerable module to minimize the risk of exploitation. Avoid using maliciously crafted ABC files in the affected software until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this issue.
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Autodesk Fbx Review