First published: Mon Apr 19 2021(Updated: )
A user may be tricked into opening a malicious FBX file which may exploit a use-after-free vulnerability in FBX's Review causing the application to reference a memory location controlled by an unauthorized third party, thereby running arbitrary code on the system.
Credit: psirt@autodesk.com
Affected Software | Affected Version | How to fix |
---|---|---|
Autodesk FBX Review | <=1.5.0 | |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Autodesk FBX Review vulnerability is CVE-2021-27031.
The severity of CVE-2021-27031 is critical with a severity value of 7.8.
Remote attackers can exploit CVE-2021-27031 by executing arbitrary code on affected installations of Autodesk FBX Review through user interaction such as visiting a malicious page or opening a malicious file.
Autodesk FBX Review versions up to and including 1.5.0 are affected by CVE-2021-27031.
Yes, users should update to a version of Autodesk FBX Review that is not affected by CVE-2021-27031.