PT-2024-19689 · Autodesk · Autodesk Fbx Review

Published

2024-03-17

·

Updated

2024-08-27

·

CVE-2024-23139

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Autodesk FBX Review versions 1.5.3.0 and prior
Description A maliciously crafted ABC file, when parsed through Autodesk FBX, may force an Out-of-Bounds Write issue. This can be leveraged to cause a crash, data corruption, or execute arbitrary code in the context of the current process. The issue is related to the parsing of ActionScript Byte Code “ABC” files, which are created by the Flash compiler and contain executable code. This issue, in conjunction with other issues, could lead to code execution in the context of the current process.
Recommendations For Autodesk FBX Review versions 1.5.3.0 and prior, consider disabling the parsing of ABC files until a patch is available. Restrict access to the vulnerable module to minimize the risk of exploitation. Avoid using maliciously crafted ABC files in the affected software until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2024-23139
ZDI-24-295

Affected Products

Autodesk Fbx Review