CVE-2022-41303
published 2022-10-14CVE-2022-41303: A user may be tricked into opening a malicious FBX file which may exploit a use-after-free vulnerability in Autodesk FBX SDK 2020 version causing the…
PriorityP336high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.35%
27.3th percentile
A user may be tricked into opening a malicious FBX file which may exploit a use-after-free vulnerability in Autodesk FBX SDK 2020 version causing the application to reference a memory location controlled by an unauthorized third party, thereby running arbitrary code on the system.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| autodesk | fbx_software_development_kit | — | — |
| msrc | 3d_viewer | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vendor_oracle9.8CRITICAL
vendor_msrc7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h48v-98vx-hfjr: A user may be tricked into opening a malicious FBX file which may exploit a use-after-free vulnerability in Autodesk FBX SDK 2020 version causing the
ghsa_unreviewed·2022-10-14
CVE-2022-41303 [HIGH] CWE-416 GHSA-h48v-98vx-hfjr: A user may be tricked into opening a malicious FBX file which may exploit a use-after-free vulnerability in Autodesk FBX SDK 2020 version causing the
A user may be tricked into opening a malicious FBX file which may exploit a use-after-free vulnerability in Autodesk FBX SDK 2020 version causing the application to reference a memory location controlled by an unauthorized third party, thereby running arbitrary code on the system.
Microsoft
AutoDesk: CVE-2022-41303 use-after-free vulnerability in Autodesk® FBX® SDK 2020 or prior
vendor_msrc·2023-09-12·CVSS 7.8
CVE-2022-41303 [HIGH] AutoDesk: CVE-2022-41303 use-after-free vulnerability in Autodesk® FBX® SDK 2020 or prior
AutoDesk: CVE-2022-41303 use-after-free vulnerability in Autodesk® FBX® SDK 2020 or prior
FAQ: Why is this AutoDesk CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in AutoDesk software which is consumed by the Microsoft products listed in the Security Updates table. It is being documented in the Security Update Guide to announce that the latest builds of these products are no longer vulnerable. Please see Security Update Guide Supports CVEs Assigned by Industry Partners for more information.
FAQ: How do I get the updated app?
The Microsoft Store will automatically update affected customers. Alternatively, customers can get the update immediately; see here for details.
It is possible for customers to disable automatic updates for the Microsoft Store. T
CISA ICS
Autodesk FBX SDK
cisa_ics·2023-03-14·CVSS 7.8
[HIGH] Autodesk FBX SDK
ICS Advisory
##
Autodesk FBX SDK
Release DateMarch 14, 2023
Alert CodeICSA-23-073-02
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Autodesk
- Equipment: FBX SDK
- Vulnerability: Out-of-bounds Read, Use After Free, Out-of-bounds Write
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could lead to code execution or a denial-of-service condition. Products using Autodesk FBX SDK software are affected by these vulnerabilities.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following versions of the affected products are affected:
- Autodesk FBX SDK versions 2020 and prior
- Luxion KeyShot version 11.3 and prior
## 3.2 VULNERABILITY OVERVIEW
3.2.1 OUT-OF-BOUNDS READ CWE-1
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Studio (Apache Shiro) — CVE-2021-41303
vendor_oracle·2022-07-15·CVSS 9.8
CVE-2021-41303 [CRITICAL] Oracle Oracle Financial Services Applications Risk Matrix: Studio (Apache Shiro) — CVE-2021-41303
Oracle Oracle Financial Services Applications Risk Matrix: Studio (Apache Shiro) vulnerability
CVE: CVE-2021-41303
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2022 (JUL 2022)
No detection rules found.
No public exploits indexed.
2022-10-14
Published