Msrc 3D Viewer vulnerabilities
14 known vulnerabilities affecting msrc/3d_viewer.
Total CVEs
14
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH13MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2024-20677HIGHCVSS 7.82024-01-09
CVE-2024-20677 [HIGH] CWE-122 Microsoft Office Remote Code Execution Vulnerability
Microsoft Office Remote Code Execution Vulnerability
Description: A security vulnerability exists in FBX that could lead to remote code execution. To mitigate this vulnerability, the ability to insert FBX files has been disabled in Word, Excel, PowerPoint and Outlook for Windows and Mac. Versions of Office that had this feature enabled will no longer have access to it. This includes Office 2019, Office 2021, Offi
msrc
CVE-2023-36739HIGHCVSS 7.82023-09-12
CVE-2023-36739 [HIGH] CWE-122 3D Viewer Remote Code Execution Vulnerability
3D Viewer Remote Code Execution Vulnerability
FAQ: According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution?
The word Remote in the title refers to the location of the attacker. This type of exploit is sometimes referred to as Arbitrary Code Execution (ACE). The attack itself is carried out locally. This means an attacker or victim needs to exe
msrc
CVE-2023-36740HIGHCVSS 7.82023-09-12
CVE-2023-36740 [HIGH] CWE-122 3D Viewer Remote Code Execution Vulnerability
3D Viewer Remote Code Execution Vulnerability
FAQ: According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution?
The word Remote in the title refers to the location of the attacker. This type of exploit is sometimes referred to as Arbitrary Code Execution (ACE). The attack itself is carried out locally. This means an attacker or victim needs to exe
msrc
CVE-2023-36760HIGHCVSS 7.82023-09-12
CVE-2023-36760 [HIGH] CWE-416 3D Viewer Remote Code Execution Vulnerability
3D Viewer Remote Code Execution Vulnerability
FAQ: According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution?
The word Remote in the title refers to the location of the attacker. This type of exploit is sometimes referred to as Arbitrary Code Execution (ACE). The attack itself is carried out locally. This means an attacker or victim needs to exe
msrc
CVE-2022-41303HIGHCVSS 7.82023-09-12
CVE-2022-41303 [HIGH] AutoDesk: CVE-2022-41303 use-after-free vulnerability in Autodesk® FBX® SDK 2020 or prior
AutoDesk: CVE-2022-41303 use-after-free vulnerability in Autodesk® FBX® SDK 2020 or prior
FAQ: Why is this AutoDesk CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in AutoDesk software which is consumed by the Microsoft products listed in the Security Updates table. It is being documented in the Security Update Guide to announce that the latest bui
msrc
CVE-2023-27911HIGHCVSS 7.82023-06-13
CVE-2023-27911 [HIGH] CWE-122 AutoDesk: CVE-2023-27911 Heap buffer overflow vulnerability in Autodesk® FBX® SDK 2020 or prior
AutoDesk: CVE-2023-27911 Heap buffer overflow vulnerability in Autodesk® FBX® SDK 2020 or prior
FAQ: Why is this AutoDesk CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in AutoDesk software which is consumed by the Microsoft products listed in the Security Updates table. It is being documented in the Security Update Guide to announce
msrc
CVE-2023-27909HIGHCVSS 7.82023-06-13
CVE-2023-27909 [HIGH] CWE-122 AutoDesk: CVE-2023-27909 Out-Of-Bounds Write Vulnerability in Autodesk® FBX® SDK 2020 or prior
AutoDesk: CVE-2023-27909 Out-Of-Bounds Write Vulnerability in Autodesk® FBX® SDK 2020 or prior
FAQ: Why is this AutoDesk CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in AutoDesk software which is consumed by the Microsoft products listed in the Security Updates table. It is being documented in the Security Update Guide to announce t
msrc
CVE-2021-43208HIGHCVSS 7.82021-11-09
CVE-2021-43208 [HIGH] 3D Viewer Remote Code Execution Vulnerability
3D Viewer Remote Code Execution Vulnerability
FAQ: How do I get the updated app?
The Microsoft Store will automatically update affected customers. Alternatively, customers can get the update immediately; see here for details.
It is possible for customers to disable automatic updates for the Microsoft Store. The Microsoft Store will not automatically install this update for those customers.
Customers using the Microsoft Store fo
msrc
CVE-2021-43209HIGHCVSS 7.82021-11-09
CVE-2021-43209 [HIGH] 3D Viewer Remote Code Execution Vulnerability
3D Viewer Remote Code Execution Vulnerability
FAQ: How do I get the updated app?
The Microsoft Store will automatically update affected customers. Alternatively, customers can get the update immediately; see here for details.
It is possible for customers to disable automatic updates for the Microsoft Store. The Microsoft Store will not automatically install this update for those customers.
Customers using the Microsoft Store fo
msrc
CVE-2021-31943HIGHCVSS 7.82021-06-08
CVE-2021-31943 [HIGH] 3D Viewer Remote Code Execution Vulnerability
3D Viewer Remote Code Execution Vulnerability
FAQ: How do I get the updated app?
The Microsoft Store will automatically update affected customers. Alternatively, customers can get the update immediately; see here for details.
It is possible for customers to disable automatic updates for the Microsoft Store. The Microsoft Store will not automatically install this update for those customers.
My system is in a disconnected environ
msrc
CVE-2021-31942HIGHCVSS 7.82021-06-08
CVE-2021-31942 [HIGH] 3D Viewer Remote Code Execution Vulnerability
3D Viewer Remote Code Execution Vulnerability
FAQ: How do I get the updated app?
The Microsoft Store will automatically update affected customers. Alternatively, customers can get the update immediately; see here for details.
It is possible for customers to disable automatic updates for the Microsoft Store. The Microsoft Store will not automatically install this update for those customers.
My system is in a disconnected environ
msrc
CVE-2021-31944MEDIUMCVSS 5.02021-06-08
CVE-2021-31944 [MEDIUM] 3D Viewer Information Disclosure Vulnerability
3D Viewer Information Disclosure Vulnerability
FAQ: How do I get the updated app?
The Microsoft Store will automatically update affected customers. Alternatively, customers can get the update immediately; see here for details.
It is possible for customers to disable automatic updates for the Microsoft Store. The Microsoft Store will not automatically install this update for those customers.
My system is in a disconnected env
msrc
CVE-2020-17003HIGHCVSS 7.82020-10-13
CVE-2020-17003 [HIGH] Base3D Remote Code Execution Vulnerability
Base3D Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists when the Base3D rendering engine improperly handles memory.
An attacker who successfully exploited the vulnerability would gain execution on a victim system.
The security update addresses the vulnerability by correcting how the Base3D rendering engine handles memory.
Microsoft Office: Microsoft Office
Issuing CNA: Microsoft
Impa
msrc
CVE-2020-16918HIGHCVSS 7.82020-10-13
CVE-2020-16918 [HIGH] Base3D Remote Code Execution Vulnerability
Base3D Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists when the Base3D rendering engine improperly handles memory.
An attacker who successfully exploited the vulnerability would gain execution on a victim system.
The security update addresses the vulnerability by correcting how the Base3D rendering engine handles memory.
FAQ: Is the Preview Pane an attack vector for this vulnerability
msrc