AUTODESK, MS OFFICE, PAINT 3D VULNERABILITY AFFECTS MILLIONS OF DEVICES

Just days after Microsoft released its update package for the month of April the company issued a new set of security patches to fix various vulnerabilities in the Office suite that could be exploited by threat actors to execute remote code.
The company also released a security update for the Paint 3D tool, as the flaw relates to a component shared by the Office suite and editing software: Autodesk’s FBX library.
Autodesk is recognized as the developer of AutoCAD, although it has many other products widely used by architects, engineers, creators of digital content, among others. In total, six vulnerabilities were fixed in its software development kit (FBX SDK).
These failures can be exploited by tricking a user into opening a specially designed FBX file, which would lead to a denial of service (DDoS) condition and arbitrary code execution. Because the Autodesk FBK library is built into vulnerable applications specially designed 3D content processing could trigger exploitation.

Comments