Junglewise Threat Intelligence

CVE-2016-9306: Autodesk FBX-SDK buffer overflows in DAE file parsing

CVE-2016-9306 · Severity: critical · CVSS 9.8 · Published 2017-01-25

Technologies: Autodesk Fbx Software Development Kit. Vendors: Autodesk.

Executive brief

Autodesk FBX-SDK is a software development kit used by developers to integrate 3D content into applications. A critical vulnerability exists where processing specially crafted 3D files can allow an attacker to take control of the system running the software. This could lead to unauthorized data access, system instability, or the execution of malicious software.

Technical details

The Autodesk FBX-SDK versions prior to 2017.1 are vulnerable to multiple buffer overflows (CWE-119) during the parsing and conversion of DAE (Digital Asset Exchange) format files. The root cause is improper restriction of operations within the bounds of a memory buffer when handling malformed file structures. An attacker can exploit this by providing a malicious DAE file to an application utilizing the SDK, potentially leading to arbitrary code execution. The vulnerability is reachable over the network if the application processes user-supplied files, and it does not require authentication or user interaction according to the CVSS assessment. Autodesk has addressed this issue in version 2017.1 of the SDK.

Affected products

  • Autodesk FBX Software Development Kit (SDK) Before 2017.1

Timeline

  • 2017-01-25: advisory: NVD published the vulnerability details.
  • 2017-01-25: disclosed: Initial disclosure of the vulnerability.

References

Related threats