Directory Traversal Remote Code Execution in Autodesk FBX Review
CVE-2021-27030

7.8HIGH

Key Information:

Vendor
Autodesk
Vendor
CVE Published:
19 April 2021

Summary

The vulnerability allows an attacker to exploit a directory traversal issue in Autodesk FBX Review. By enticing a user to open a specially crafted FBX file, the attacker could execute arbitrary code on the victim's system. This occurs due to insufficient validation of file paths, which may lead to unauthorized access to system resources. Users are advised to avoid opening untrusted FBX files and apply any available security updates from Autodesk.

Affected Version(s)

Autodesk FBX Review 1.4.1.0

References

EPSS Score

49% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.