CVE-2020-7085 is a heap overflow vulnerability in Autodesk FBX-SDK versions 2019.2 and earlier, which could allow for arbitrary code execution on affected systems. With a CVSS score of 7.8 (HIGH), it requires user interaction (UI:R) and local access (AV:L), but has high impacts on confidentiality, integrity, and availability. While not listed in CISA's KEV catalog and lacking public exploit code on platforms like Metasploit or ExploitDB, it has garnered some community discussion and media coverage, including an advisory from Microsoft.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2019.2CPE matchmatch criteria | cpe:2.3:a:autodesk:fbx_software_development_kit:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.