CVE-2021-27028: Autodesk FBX Review FBX File Parsing Memory Corruption Remote Code Execution Vulnerability
A Memory Corruption Vulnerability in Autodesk FBX Review version 1.5.0 and prior may lead to remote code execution through maliciously crafted DLL files.
Other sources
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autodesk FBX Review. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of FBX files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.
— ZDI
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-27028?
CVE-2021-27028 has a high severity rating due to its potential for remote code execution.
How do I fix CVE-2021-27028?
To fix CVE-2021-27028, upgrade to Autodesk FBX Review version 1.5.1 or later.
What types of attacks can exploit CVE-2021-27028?
CVE-2021-27028 can be exploited via maliciously crafted DLL files to execute arbitrary code.
Which versions of Autodesk FBX Review are affected by CVE-2021-27028?
CVE-2021-27028 affects Autodesk FBX Review versions 1.5.0 and prior.
Is user interaction required to exploit CVE-2021-27028?
Yes, user interaction is required to exploit CVE-2021-27028 by opening a malicious file.