Impact
Autodesk FBX SDK contains a stack‑based buffer overflow in the fbxsdk::ExtractDrive routine that is triggered when parsing a specially crafted FBX file. When this vulnerability is exploited, an attacker can execute arbitrary code within the process that is running the SDK, effectively taking control of that process in the user’s context.
Affected Systems
The flaw affects Autodesk FBX SDK version 2020.3.9 and any installations that rely on that specific build. No other versions or products are currently listed as vulnerable.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity vulnerability. The EPSS score is not available, and the flaw is not listed in the CISA KEV catalog. The likely attack vector involves locally delivering a malicious FBX file to the SDK, such as by opening it or importing it within a trusted application. Because the flaw results in code execution in the context of the current process, it can lead to local privilege escalation or complete compromise of the host if the SDK runs with elevated rights.
OpenCVE Enrichment