
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2022-41302 is an Out-Of-Bounds Read vulnerability affecting Autodesk FBX SDK version 2020 and prior versions. The vulnerability was discovered and disclosed on September 14, 2022, impacting applications and services utilizing the Autodesk FBX SDK software. This security flaw could potentially lead to code execution or information disclosure when processing maliciously crafted FBX files (Autodesk Advisory).
The vulnerability is classified as a high-severity issue with a CVSS v3 base score of 7.8 (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). When exploited alongside other vulnerabilities, it could result in code execution in the context of the current process. The vulnerability specifically involves an out-of-bounds read condition that occurs when processing maliciously crafted FBX files (CISA Advisory).
Successful exploitation of this vulnerability could lead to code execution or information disclosure. The vulnerability affects products using Autodesk FBX SDK software, potentially compromising the security of applications that process FBX files (CISA Advisory).
The vulnerability requires local access and user interaction to exploit. While the attack complexity is considered low, there are no known public exploits specifically targeting this vulnerability (CISA Advisory).
Autodesk recommends users of the affected products apply the available hotfix for their version via the Autodesk Desktop App. The vulnerability has been fixed in FBX SDK version 2020.3.2. For third-party developers who use FBXSDK in their applications or services, it is recommended to obtain and apply the latest version of the FBXSDK (Autodesk Advisory).
The vulnerability was reported by msrc-tyler and msrcdaniel from Microsoft's MSRC working with HackerOne, demonstrating collaborative efforts in the security community to identify and address potential threats (Autodesk Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."