CVE-2022-41303 is a use-after-free vulnerability in Autodesk FBX SDK 2020 that allows arbitrary code execution when a user opens a specially crafted FBX file. This high-severity vulnerability (CVSS 7.8) requires user interaction and local access, but can lead to complete compromise of confidentiality, integrity, and availability. While no public exploits or active exploitation have been observed, and it is not listed in CISA's KEV catalog, it has received limited community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2020.0CPE matchmatch criteria | cpe:2.3:a:autodesk:fbx_software_development_kit:2020.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.