Junglewise Threat Intelligence

CVE-2016-9307: Autodesk FBX SDK buffer overflows in 3DS file processing

CVE-2016-9307 · Severity: critical · CVSS 9.8 · Published 2017-01-25

Technologies: Autodesk Fbx Software Development Kit. Vendors: Autodesk.

Executive brief

The Autodesk FBX SDK, a tool used by developers to integrate 3D content into applications, is vulnerable to a critical security flaw. By providing a specially crafted 3D file, an attacker could potentially take control of a system or execute unauthorized commands. This could lead to a total compromise of the application using the SDK and the data it processes.

Technical details

The Autodesk FBX SDK versions prior to 2017.1 are affected by multiple buffer overflow vulnerabilities (CWE-119). The root cause is improper memory management when the SDK processes or converts malformed 3DS format files. An attacker can exploit this by delivering a malicious 3DS file to an application that utilizes the vulnerable SDK. Successful exploitation can lead to arbitrary code execution with the privileges of the application. The vulnerability is reachable over the network if the application processes user-supplied files, and it does not require authentication.

Affected products

  • Autodesk FBX Software Development Kit Before 2017.1

Timeline

  • 2017-01-25: advisory: NVD publication date
  • 2017-01-25: disclosed: Initial disclosure of the vulnerability

References

Related threats