A maliciously crafted ABC file, when parsed through Autodesk FBX, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
                
            References
                    | Link | Resource | 
|---|---|
| https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0005 | Vendor Advisory | 
| https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0005 | Vendor Advisory | 
Configurations
                    History
                    16 Apr 2025, 18:13
| Type | Values Removed | Values Added | 
|---|---|---|
| CPE | cpe:2.3:a:autodesk:fbx_review:1.5.3:*:*:*:*:*:*:* | |
| First Time | Autodesk Autodesk fbx Review | |
| References | () https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0005 - Vendor Advisory | 
10 Feb 2025, 21:15
| Type | Values Removed | Values Added | 
|---|---|---|
| Summary | (en) A maliciously crafted ABC file, when parsed through Autodesk FBX, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process. | 
28 Jan 2025, 20:15
| Type | Values Removed | Values Added | 
|---|---|---|
| Summary | (en) An Out-Of-Bounds Write Vulnerability in Autodesk FBX Review version 1.5.3.0 and prior may lead to code execution or information disclosure through maliciously crafted ActionScript Byte Code “ABC” files. ABC files are created by the Flash compiler and contain executable code. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process. | 
Information
                Published : 2024-03-18 00:15
Updated : 2025-04-16 18:13
NVD link : CVE-2024-23139
Mitre link : CVE-2024-23139
CVE.ORG link : CVE-2024-23139
JSON object : View
Products Affected
                autodesk
- fbx_review
CWE
                
                    
                        
                        CWE-787
                        
            Out-of-bounds Write
