CVE-2022-41303: Use After Free
A user may be tricked into opening a malicious FBX file which may exploit a use-after-free vulnerability in Autodesk FBX SDK 2020 version causing the application to reference a memory location controlled by an unauthorized third party, thereby running arbitrary code on the system.
Other sources
AutoDesk: CVE-2022-41303 use-after-free vulnerability in Autodesk® FBX® SDK 2020 or prior
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Apply mitigation for the Autodesk® FBX® SDK use-after-free issue (CVE-2022-41303) by preventing users from opening untrusted FBX files (e.g., block/disable processing of externally sourced FBX files in your content pipeline) to avoid triggering the vulnerability.
Event History
Frequently Asked Questions
What is CVE-2022-41303?
CVE-2022-41303 is a use-after-free vulnerability in Autodesk® FBX® SDK 2020 or prior.
What software is affected by CVE-2022-41303?
Autodesk® FBX® SDK 2020 or prior is affected by CVE-2022-41303.
How severe is CVE-2022-41303?
CVE-2022-41303 has a severity rating of high (7).
How can I fix CVE-2022-41303?
To fix CVE-2022-41303, update to a version of Autodesk® FBX® SDK that is 2020 or later.
Is there any additional information about CVE-2022-41303?
For more information about CVE-2022-41303, you can refer to the Microsoft Security Response Center's update guide.