Impact
A maliciously crafted FBX file triggers a stack-based buffer overflow in the Autodesk FBX SDK’s BinaryReadSectionHeader function, allowing an attacker to execute arbitrary code within the context of the current process. The vulnerability directly impacts code execution and can compromise the confidentiality, integrity, and availability of any application that loads untrusted FBX files.
Affected Systems
Autodesk FBX SDK, version 2020.3.9. The CPE data indicates that this particular release is vulnerable; other releases are not documented in the provided data.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity, and the EPSS score is not available, though the vulnerability is not listed in CISA KEV. The likely attack vector is the delivery of a specially crafted FBX file that the SDK processes, which could occur via local file import or remote file transfer. The absence of a publicly known exploit does not mitigate the potential risk, as the flaw permits arbitrary code execution once the vulnerable function is invoked.
OpenCVE Enrichment