A maliciously crafted ABC file, when parsed through Autodesk FBX, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
References
Link | Resource |
---|---|
https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0005 | Vendor Advisory |
https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0005 | Vendor Advisory |
Configurations
History
16 Apr 2025, 18:13
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:autodesk:fbx_review:1.5.3:*:*:*:*:*:*:* | |
First Time |
Autodesk
Autodesk fbx Review |
|
References | () https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0005 - Vendor Advisory |
10 Feb 2025, 21:15
Type | Values Removed | Values Added |
---|---|---|
Summary | (en) A maliciously crafted ABC file, when parsed through Autodesk FBX, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process. |
28 Jan 2025, 20:15
Type | Values Removed | Values Added |
---|---|---|
Summary | (en) An Out-Of-Bounds Write Vulnerability in Autodesk FBX Review version 1.5.3.0 and prior may lead to code execution or information disclosure through maliciously crafted ActionScript Byte Code “ABC” files. ABC files are created by the Flash compiler and contain executable code. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process. |
Information
Published : 2024-03-18 00:15
Updated : 2025-04-16 18:13
NVD link : CVE-2024-23139
Mitre link : CVE-2024-23139
CVE.ORG link : CVE-2024-23139
JSON object : View
Products Affected
autodesk
- fbx_review
CWE
CWE-787
Out-of-bounds Write