CVE-2023-27910 is a stack buffer overflow vulnerability in Autodesk FBX SDK 2020 and prior versions, allowing an attacker to achieve code execution if a user opens a specially crafted malicious FBX file. This vulnerability carries a high CVSS score of 7.8, indicating a local attack vector with low complexity, but requiring user interaction, and potentially leading to high impact on confidentiality, integrity, and availability. While it has a low EPSS score and is not listed in CISA's KEV catalog, there is no public exploit code available (Metasploit, Nuclei, ExploitDB), and community discussion and media coverage are minimal, suggesting it is not currently under active widespread exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2020.0, < 2020.3.4CPE matchmatch criteria | cpe:2.3:a:autodesk:fbx_software_development_kit:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.