CVE-2022-41302
published 2022-10-14CVE-2022-41302: An Out-Of-Bounds Read Vulnerability in Autodesk FBX SDK version 2020. and prior may lead to code execution or information disclosure through maliciously…
PriorityP336high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.28%
19.7th percentile
An Out-Of-Bounds Read Vulnerability in Autodesk FBX SDK version 2020. and prior may lead to code execution or information disclosure through maliciously crafted FBX files. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| autodesk | fbx_software_development_kit | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Autodesk FBX SDK
cisa_ics·2023-03-14·CVSS 7.8
[HIGH] Autodesk FBX SDK
ICS Advisory
##
Autodesk FBX SDK
Release DateMarch 14, 2023
Alert CodeICSA-23-073-02
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Autodesk
- Equipment: FBX SDK
- Vulnerability: Out-of-bounds Read, Use After Free, Out-of-bounds Write
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could lead to code execution or a denial-of-service condition. Products using Autodesk FBX SDK software are affected by these vulnerabilities.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following versions of the affected products are affected:
- Autodesk FBX SDK versions 2020 and prior
- Luxion KeyShot version 11.3 and prior
## 3.2 VULNERABILITY OVERVIEW
3.2.1 OUT-OF-BOUNDS READ CWE-1
GHSA
GHSA-268r-qqf3-5wj6: An Out-Of-Bounds Read Vulnerability in Autodesk FBX SDK version 2020
ghsa_unreviewed·2022-10-14
CVE-2022-41302 [HIGH] CWE-125 GHSA-268r-qqf3-5wj6: An Out-Of-Bounds Read Vulnerability in Autodesk FBX SDK version 2020
An Out-Of-Bounds Read Vulnerability in Autodesk FBX SDK version 2020. and prior may lead to code execution or information disclosure through maliciously crafted FBX files. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-10-14
Published