Msrc 3D Viewer vulnerabilities

14 known vulnerabilities affecting msrc/3d_viewer.

Total CVEs
14
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH13MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2024-20677HIGHCVSS 7.82024-01-09
CVE-2024-20677 [HIGH] CWE-122 Microsoft Office Remote Code Execution Vulnerability Microsoft Office Remote Code Execution Vulnerability Description: A security vulnerability exists in FBX that could lead to remote code execution. To mitigate this vulnerability, the ability to insert FBX files has been disabled in Word, Excel, PowerPoint and Outlook for Windows and Mac. Versions of Office that had this feature enabled will no longer have access to it. This includes Office 2019, Office 2021, Offi
msrc
CVE-2023-36739HIGHCVSS 7.82023-09-12
CVE-2023-36739 [HIGH] CWE-122 3D Viewer Remote Code Execution Vulnerability 3D Viewer Remote Code Execution Vulnerability FAQ: According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution? The word Remote in the title refers to the location of the attacker. This type of exploit is sometimes referred to as Arbitrary Code Execution (ACE). The attack itself is carried out locally. This means an attacker or victim needs to exe
msrc
CVE-2023-36740HIGHCVSS 7.82023-09-12
CVE-2023-36740 [HIGH] CWE-122 3D Viewer Remote Code Execution Vulnerability 3D Viewer Remote Code Execution Vulnerability FAQ: According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution? The word Remote in the title refers to the location of the attacker. This type of exploit is sometimes referred to as Arbitrary Code Execution (ACE). The attack itself is carried out locally. This means an attacker or victim needs to exe
msrc
CVE-2023-36760HIGHCVSS 7.82023-09-12
CVE-2023-36760 [HIGH] CWE-416 3D Viewer Remote Code Execution Vulnerability 3D Viewer Remote Code Execution Vulnerability FAQ: According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution? The word Remote in the title refers to the location of the attacker. This type of exploit is sometimes referred to as Arbitrary Code Execution (ACE). The attack itself is carried out locally. This means an attacker or victim needs to exe
msrc
CVE-2022-41303HIGHCVSS 7.82023-09-12
CVE-2022-41303 [HIGH] AutoDesk: CVE-2022-41303 use-after-free vulnerability in Autodesk® FBX® SDK 2020 or prior AutoDesk: CVE-2022-41303 use-after-free vulnerability in Autodesk® FBX® SDK 2020 or prior FAQ: Why is this AutoDesk CVE included in the Security Update Guide? The vulnerability assigned to this CVE is in AutoDesk software which is consumed by the Microsoft products listed in the Security Updates table. It is being documented in the Security Update Guide to announce that the latest bui
msrc
CVE-2023-27911HIGHCVSS 7.82023-06-13
CVE-2023-27911 [HIGH] CWE-122 AutoDesk: CVE-2023-27911 Heap buffer overflow vulnerability in Autodesk® FBX® SDK 2020 or prior AutoDesk: CVE-2023-27911 Heap buffer overflow vulnerability in Autodesk® FBX® SDK 2020 or prior FAQ: Why is this AutoDesk CVE included in the Security Update Guide? The vulnerability assigned to this CVE is in AutoDesk software which is consumed by the Microsoft products listed in the Security Updates table. It is being documented in the Security Update Guide to announce
msrc
CVE-2023-27909HIGHCVSS 7.82023-06-13
CVE-2023-27909 [HIGH] CWE-122 AutoDesk: CVE-2023-27909 Out-Of-Bounds Write Vulnerability in Autodesk® FBX® SDK 2020 or prior AutoDesk: CVE-2023-27909 Out-Of-Bounds Write Vulnerability in Autodesk® FBX® SDK 2020 or prior FAQ: Why is this AutoDesk CVE included in the Security Update Guide? The vulnerability assigned to this CVE is in AutoDesk software which is consumed by the Microsoft products listed in the Security Updates table. It is being documented in the Security Update Guide to announce t
msrc
CVE-2021-43208HIGHCVSS 7.82021-11-09
CVE-2021-43208 [HIGH] 3D Viewer Remote Code Execution Vulnerability 3D Viewer Remote Code Execution Vulnerability FAQ: How do I get the updated app? The Microsoft Store will automatically update affected customers. Alternatively, customers can get the update immediately; see here for details. It is possible for customers to disable automatic updates for the Microsoft Store. The Microsoft Store will not automatically install this update for those customers. Customers using the Microsoft Store fo
msrc
CVE-2021-43209HIGHCVSS 7.82021-11-09
CVE-2021-43209 [HIGH] 3D Viewer Remote Code Execution Vulnerability 3D Viewer Remote Code Execution Vulnerability FAQ: How do I get the updated app? The Microsoft Store will automatically update affected customers. Alternatively, customers can get the update immediately; see here for details. It is possible for customers to disable automatic updates for the Microsoft Store. The Microsoft Store will not automatically install this update for those customers. Customers using the Microsoft Store fo
msrc
CVE-2021-31943HIGHCVSS 7.82021-06-08
CVE-2021-31943 [HIGH] 3D Viewer Remote Code Execution Vulnerability 3D Viewer Remote Code Execution Vulnerability FAQ: How do I get the updated app? The Microsoft Store will automatically update affected customers. Alternatively, customers can get the update immediately; see here for details. It is possible for customers to disable automatic updates for the Microsoft Store. The Microsoft Store will not automatically install this update for those customers. My system is in a disconnected environ
msrc
CVE-2021-31942HIGHCVSS 7.82021-06-08
CVE-2021-31942 [HIGH] 3D Viewer Remote Code Execution Vulnerability 3D Viewer Remote Code Execution Vulnerability FAQ: How do I get the updated app? The Microsoft Store will automatically update affected customers. Alternatively, customers can get the update immediately; see here for details. It is possible for customers to disable automatic updates for the Microsoft Store. The Microsoft Store will not automatically install this update for those customers. My system is in a disconnected environ
msrc
CVE-2021-31944MEDIUMCVSS 5.02021-06-08
CVE-2021-31944 [MEDIUM] 3D Viewer Information Disclosure Vulnerability 3D Viewer Information Disclosure Vulnerability FAQ: How do I get the updated app? The Microsoft Store will automatically update affected customers. Alternatively, customers can get the update immediately; see here for details. It is possible for customers to disable automatic updates for the Microsoft Store. The Microsoft Store will not automatically install this update for those customers. My system is in a disconnected env
msrc
CVE-2020-17003HIGHCVSS 7.82020-10-13
CVE-2020-17003 [HIGH] Base3D Remote Code Execution Vulnerability Base3D Remote Code Execution Vulnerability Description: A remote code execution vulnerability exists when the Base3D rendering engine improperly handles memory. An attacker who successfully exploited the vulnerability would gain execution on a victim system. The security update addresses the vulnerability by correcting how the Base3D rendering engine handles memory. Microsoft Office: Microsoft Office Issuing CNA: Microsoft Impa
msrc
CVE-2020-16918HIGHCVSS 7.82020-10-13
CVE-2020-16918 [HIGH] Base3D Remote Code Execution Vulnerability Base3D Remote Code Execution Vulnerability Description: A remote code execution vulnerability exists when the Base3D rendering engine improperly handles memory. An attacker who successfully exploited the vulnerability would gain execution on a victim system. The security update addresses the vulnerability by correcting how the Base3D rendering engine handles memory. FAQ: Is the Preview Pane an attack vector for this vulnerability
msrc