CVE-2016-9305

CRITICAL

Autodesk FBX-SDK <2017.1 - Code Injection

Title source: llm
STIX 2.1

Description

Improper handling in the Autodesk FBX-SDK before 2017.1 of type mismatches and previously deleted objects related to reading and converting malformed FBX format files can allow attackers to gain access to uninitialized pointers.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/95803

Scores

CVSS v3 9.8
EPSS 0.0058
EPSS Percentile 69.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-19
Status published
Products (1)
autodesk/fbx_software_development_kit < 2017.0
Published Jan 25, 2017
Tracked Since Feb 18, 2026