Quantcast
Channel: Tenable Blog
Viewing all articles
Browse latest Browse all 1935

ADV200004: Microsoft Releases Out-of-Band Advisory to Address Flaws in Autodesk Filmbox (FBX) Library

$
0
0

Microsoft responds to a recent security advisory from Autodesk by publishing an out-of-band advisory for Office products integrating the Autodesk library.

Background

On April 15, Autodesk released a security advisory, ADSK-SA-2020-0002, to address six vulnerabilities in the Autodesk Filmbox (FBX) Software Development Kit, which “allows application and content vendors to transfer existing content into the FBX format with minimal effort.”

In response to Autodesk’s advisory, Microsoft issued an out-of-band advisory, ADV200004, on April 21, as the FBX library is integrated into specific versions of Microsoft Office, Office 365 ProPlus and Paint 3D.

Analysis

In ADSK-SA-2020-0002, Autodesk patched the following six vulnerabilities:

CVEVulnerabilityImpactCVSSv3.x*
CVE-2020-7080Buffer OverflowArbitrary Code Execution7.8
CVE-2020-7081Type ConfusionArbitrary Code Execution, Denial of ServiceN/A
CVE-2020-7082Use-After-FreeArbitrary Code ExecutionN/A
CVE-2020-7083Integer OverflowDenial of ServiceN/A
CVE-2020-7084Null Pointer DereferenceDenial of Service5.5
CVE-2020-7085Heap OverflowArbitrary Code Execution7.8

*Please note that the CVSSv3.x scores referenced in the table above were available at the time this blog post was published and may be subject to change.

Though not all the vulnerabilities had CVSSv3.x scores assigned in their U.S. National Vulnerability Database entries, Autodesk collectively rated their advisory as High.

Exploitation of these vulnerabilities requires an attacker to convince their victim to open a malicious Microsoft Office, Office 365 ProPlus or Paint 3D file that contains specially crafted 3D content which takes advantage of the vulnerabilities in the FBX library.

Proof of concept

F-Secure researcher Max Van Amerongen, credited with the discovery of CVE-2020-7085, has tweeted a proof-of-concept video demonstrating the heap overflow vulnerability:

Solution

Microsoft’s advisory states that it has addressed these vulnerabilities in the following products:

ProductVersionKnowledge Base Article
Microsoft Office 2016Click-to-Run 32-bit and 64-bit editionsOffice 2016 C2R
Microsoft Office 201932-bit and 64-bit editionsOffice 2019
Office 365 ProPlus32-bit and 64-bit editionsOffice 365 ProPlus
Paint 3DPaint 3D Release Notes

However, at the time this blog post was published, there were no new updates to the articles listed above. The last time these articles were updated was on April 14, which coincided with April’s Patch Tuesday release. It is unclear if Microsoft plans to release its updates as part of this out-of-band release, or if the fixes will be included as part of May’s Patch Tuesday release.

Since FBX is an included library in these versions of Office and Paint 3D and Microsoft released an out-of-band advisory for these flaws, we strongly encourage organizations to apply these patches as soon as they are available.

Identifying affected systems

A list of Tenable plugins to identify these vulnerabilities will appear here as they’re released.

Get more information

Join Tenable's Security Response Team on the Tenable Community.

Learn more about Tenable, the first Cyber Exposure platform for holistic management of your modern attack surface.

Get a free 30-day trial of Tenable.io Vulnerability Management.


Viewing all articles
Browse latest Browse all 1935

Trending Articles