CVE-2023-27909 is an Out-Of-Bounds Write vulnerability in Autodesk FBX SDK versions 2020 and prior. This flaw can lead to code execution or information disclosure when processing maliciously crafted FBX files. With a CVSS score of 7.8 (High), it requires user interaction (UI:R) but has low attack complexity (AC:L) and can result in high impact to confidentiality, integrity, and availability (C:H/I:H/A:H). There is no evidence of active exploitation (KEV: No), nor are there public exploits available on Metasploit or ExploitDB, though it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2020.0, < 2020.3.4CPE matchmatch criteria | cpe:2.3:a:autodesk:fbx_software_development_kit:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.