Junglewise Threat Intelligence

CVE-2016-9305: Autodesk FBX-SDK uninitialized pointer access in FBX parsing

CVE-2016-9305 · Severity: critical · CVSS 9.8 · Published 2017-01-25

Technologies: Autodesk Fbx Software Development Kit. Vendors: Autodesk.

Executive brief

The Autodesk FBX SDK, a tool used by developers to integrate 3D data exchange into their applications, contains a critical vulnerability in how it processes FBX files. An attacker could provide a specially crafted, malicious file that, when opened or converted by an application using this library, could allow them to gain unauthorized access to system memory. This could lead to the theft of sensitive information, system crashes, or the execution of malicious code, potentially compromising the entire application and the data it handles.

Technical details

A vulnerability exists in the Autodesk FBX-SDK versions prior to 2017.1 due to improper data processing during the reading and conversion of FBX format files. Specifically, the SDK fails to correctly handle type mismatches and references to previously deleted objects within malformed files. This flaw allows an attacker to trigger access to uninitialized pointers. Given the CVSS score and vector, this is categorized as a remote attack that requires no authentication or user interaction, potentially leading to full compromise of confidentiality, integrity, and availability (RCE or information disclosure). The issue is resolved in FBX-SDK version 2017.1.

Affected products

  • Autodesk FBX Software Development Kit (SDK) Before 2017.1

Timeline

  • 2017-01-25: disclosed
  • 2017-01-25: advisory: NVD publication date

References

Related threats