2024-08-27 16:03:16 +00:00

60 lines
2.3 KiB
JSON

{
"id": "CVE-2024-23139",
"sourceIdentifier": "psirt@autodesk.com",
"published": "2024-03-18T00:15:07.663",
"lastModified": "2024-08-27T14:35:02.770",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "An Out-Of-Bounds Write Vulnerability in Autodesk FBX Review version 1.5.3.0 and prior may lead to code execution or information disclosure through maliciously crafted ActionScript Byte Code \u201cABC\u201d files. ABC files are created by the Flash compiler and contain executable code. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.\n"
},
{
"lang": "es",
"value": "Una vulnerabilidad de escritura fuera de los l\u00edmites en Autodesk FBX Review versi\u00f3n 1.5.3.0 y anteriores puede provocar la ejecuci\u00f3n de c\u00f3digo o la divulgaci\u00f3n de informaci\u00f3n a trav\u00e9s de archivos de c\u00f3digo de bytes \u201cABC\u201d de ActionScript creados con fines malintencionados. Los archivos ABC son creados por el compilador Flash y contienen c\u00f3digo ejecutable. Esta vulnerabilidad, junto con otras vulnerabilidades, podr\u00eda provocar la ejecuci\u00f3n de c\u00f3digo en el contexto del proceso actual."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"attackVector": "LOCAL",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "REQUIRED",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH",
"baseScore": 7.8,
"baseSeverity": "HIGH"
},
"exploitabilityScore": 1.8,
"impactScore": 5.9
}
]
},
"weaknesses": [
{
"source": "psirt@autodesk.com",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-787"
}
]
}
],
"references": [
{
"url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2024-0005",
"source": "psirt@autodesk.com"
}
]
}