Vulnerabilities > CVE-2021-27031 - Use After Free vulnerability in Autodesk FBX Review 1.4.0/1.4.1.0/1.5.0
Attack vector
LOCAL Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
A user may be tricked into opening a malicious FBX file which may exploit a use-after-free vulnerability in FBX's Review causing the application to reference a memory location controlled by an unauthorized third party, thereby running arbitrary code on the system.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 4 |
Common Weakness Enumeration (CWE)
References
- https://www.autodesk.com/trust/security-advisories/adsk-sa-2021-0001
- https://www.autodesk.com/trust/security-advisories/adsk-sa-2021-0001
- https://www.zerodayinitiative.com/advisories/ZDI-21-1069/
- https://www.zerodayinitiative.com/advisories/ZDI-21-1069/
- https://www.zerodayinitiative.com/advisories/ZDI-21-468/
- https://www.zerodayinitiative.com/advisories/ZDI-21-468/