ADV200004: Microsoft Releases Out-of-Band Advisory to Address Flaws in Autodesk Filmbox (FBX) Library
Microsoft responds to a recent security advisory from Autodesk by publishing an out-of-band advisory for Office products integrating the Autodesk library.
背景
On April 15, Autodesk released a security advisory, ADSK-SA-2020-0002, to address six vulnerabilities in the Autodesk Filmbox (FBX) Software Development Kit, which “allows application and content vendors to transfer existing content into the FBX format with minimal effort.”
In response to Autodesk’s advisory, Microsoft issued an out-of-band advisory, ADV200004, on April 21, as the FBX library is integrated into specific versions of Microsoft Office, Office 365 ProPlus and Paint 3D.
分析
In ADSK-SA-2020-0002, Autodesk patched the following six vulnerabilities:
CVE | Vulnerability | Impact | CVSSv3.x* |
---|---|---|---|
CVE-2020-7080 | Buffer Overflow | Arbitrary Code Execution | 7.8 |
CVE-2020-7081 | Type Confusion | Arbitrary Code Execution, Denial of Service | 不适用 |
CVE-2020-7082 | Use-After-Free | Arbitrary Code Execution | 不适用 |
CVE-2020-7083 | Integer Overflow | Denial of Service | 不适用 |
CVE-2020-7084 | Null Pointer Dereference | Denial of Service | 5.5 |
CVE-2020-7085 | Heap Overflow | Arbitrary Code Execution | 7.8 |
*Please note that the CVSSv3.x scores referenced in the table above were available at the time this blog post was published and may be subject to change.
Though not all the vulnerabilities had CVSSv3.x scores assigned in their U.S. National Vulnerability Database entries, Autodesk collectively rated their advisory as High.
Exploitation of these vulnerabilities requires an attacker to convince their victim to open a malicious Microsoft Office, Office 365 ProPlus or Paint 3D file that contains specially crafted 3D content which takes advantage of the vulnerabilities in the FBX library.
概念验证
F-Secure researcher Max Van Amerongen, credited with the discovery of CVE-2020-7085, has tweeted a proof-of-concept video demonstrating the heap overflow vulnerability:
My Autodesk FBX Heap Overflow (CVE-2020-7085) has now been disclosed at https://t.co/jvumWcCZE7
— maxpl0it (@maxpl0it) April 17, 2020
Works on FBX SDK < 2019.5
PoC video from disclosure: pic.twitter.com/vayCIomgaP
解决方案
Microsoft’s advisory states that it has addressed these vulnerabilities in the following products:
产品 | Version | Knowledge Base Article |
---|---|---|
Microsoft Office 2016 | Click-to-Run 32-bit and 64-bit editions | Office 2016 C2R |
Microsoft Office 2019 | 32-bit and 64-bit editions | Office 2019 |
Office 365 ProPlus | 32-bit and 64-bit editions | Office 365 ProPlus |
Paint 3D | Paint 3D Release Notes |
However, at the time this blog post was published, there were no new updates to the articles listed above. The last time these articles were updated was on April 14, which coincided with April’s Patch Tuesday release. It is unclear if Microsoft plans to release its updates as part of this out-of-band release, or if the fixes will be included as part of May’s Patch Tuesday release.
Since FBX is an included library in these versions of Office and Paint 3D and Microsoft released an out-of-band advisory for these flaws, we strongly encourage organizations to apply these patches as soon as they are available.
识别受影响的系统
用于识别这些漏洞的 Tenable 插件列表在发布时将显示在此处。
获取更多信息
加入 Tenable Community 中的 Tenable 安全响应团队
了解有关 Tenable 这款首创 Cyber Exposure 平台的更多信息,全面管理现代攻击面。
获取 30 天免费试用版 Tenable.io Vulnerability Management。
相关文章
- Vulnerability Management