Autodesk FBX|¶à¸ö°²È«·ì϶¹«¸æ

°ä²¼¹¦·ò 2020-04-24

0x00 ·ì϶¸ÅÊö



²úÆ·

CVE ID

Àà ÐÍ

·ì϶µÈ¼¶

Ô¶³ÌÀûÓÃ

Autodesk FBX-SDK <= 2019.0

CVE-2020-7080

BO

¸ßΣ

·ñ

CVE-2020-7081

TC

¸ßΣ

·ñ

CVE-2020-7082

UAF

¸ßΣ

·ñ

CVE-2020-7083

IO

ÖÐΣ

·ñ

CVE-2020-7084

NPD

ÖÐΣ

·ñ

Autodesk FBX-SDK <= 2019.2

CVE-2020-7085

HO

¸ßΣ

·ñ


0x01 ·ì϶ÏêÇé


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

Autodesk FBX-SDKÊÇÃÀ¹úÅ·ÌØ¿Ë£¨Autodesk£©¹«Ë¾µÄÒ»¿îC++Èí¼þ¿ª·¢Æ½Ì¨ºÍAPI¹¤¾ß°ü £¬ËüÖØÒªÓÃÓÚ½«ÏÖÓÐÄÚÈÝת»»ÎªFBXÌåʽ¡£

4ÔÂ15ÈÕ £¬Autodesk¹Ù·½°ä²¼²¼¸æÅú×¢ÀûÓÃFBX-SDK <= 2020.0°æ±¾µÄÀûÓ÷¨Ê½ºÍ·þÎñ¿ÉÄÜ»áÊܵ½»º³åÇøÒç³ö £¬ÀàÐÍ»ìºÏ £¬¿ªÊͺó³ÁÓà £¬ÕûÊýÒç³ö £¬¿ÕÖ¸Õë½âÒýÓúͶÑÒç¶Âí½ÅµÄÓ°Ïì¡£·ì϶¾ßÌåÐÅÏ¢ÈçÏ£º

CVE-2020-7080 ÊÇAutodesk FBX-SDK»º³åÇøÒç¶Âí½Å¡£¹¥»÷Õß¿ÉÄÜ»áÓÕÆ­Óû§´ò¿ªÒ»¸ö¶ñÒâFBXÎļþ £¬µ¼ÖÂÔÚϵͳÉÏÖ´ÐÐËÁÒâ´úÂë¡£CVSSÆÀ·Ö7.8¡£

CVE-2020-7081 ÊÇAutodesk FBX-SDKÀàÐÍ»ìºÏ·ì϶¡£¹¥»÷Õß¿ÉÄÜ»áÓÕÆ­Óû§´ò¿ªÒ»¸ö¶ñÒâFBXÎļþ £¬µ¼ÖÂÆä¶ÁÈ¡/дÈëÔ½½çÄÚ´æµØÎ»»òÔÚϵͳÉÏÔËÐÐËÁÒâ´úÂë £¬»òÕßµ¼Ö»ؾø·þÎñ¡£CVSSÆÀ·Ö8.8¡£

CVE-2020-7082 ÊÇAutodesk FBX-SDK¿ªÊͺó³ÁÓ÷ì϶¡£¹¥»÷Õß¿ÉÄÜ»áÓÕÆ­Óû§´ò¿ªÒ»¸ö¶ñÒâFBXÎļþ £¬µ¼Ö¸ÃÀûÓ÷¨Ê½ÒýÓÃÓÉδ¾­ÊÚȨµÄµÚÈý·½½ÚÔìµÄÄÚ´æµØÎ» £¬ÔÚϵͳÉÏÔËÐÐËÁÒâ´úÂë¡£CVSSÆÀ·Ö8.8¡£

CVE-2020-7083 ÊÇAutodesk FBX-SDKÕûÊýÒç¶Âí½Å¡£¹¥»÷Õß¿ÉÄÜ»áÓÕÆ­Óû§´ò¿ªÒ»¸ö¶ñÒâFBXÎļþ £¬Ê¹ÀûÓ÷¨Ê½±ÀÀ£µ¼Ö»ؾø·þÎñ¡£CVSSÆÀ·Ö6.5¡£

CVE-2020-7084 ÊÇAutodesk FBX-SDK ¿ÕÖ¸Õë½âÒýÓ÷ì϶¡£¹¥»÷Õß¿ÉÄÜ»áÓÕÆ­Óû§´ò¿ªÒ»¸ö¶ñÒâFBXÎļþ £¬Ê¹ÀûÓ÷¨Ê½±ÀÀ£µ¼Ö»ؾø·þÎñ¡£CVSSÆÀ·Ö5.5¡£

CVE-2020-7085 ÊÇAutodesk FBX-SDK ¶ÑÒç¶Âí½Å¡£¹¥»÷Õß¿ÉÄÜ»áÓÕÆ­Óû§´ò¿ªÒ»¸ö¶ñÒâFBXÎļþ £¬¸ÃÎļþ½«Í¨¹ý¸ü¸ÄFBXÎļþÖеÄijЩÖ·´Å²ÓÃÓжÑÒç¶Âí½ÅµÄFBX½âÎöÆ÷À´»ñÈ¡ÓÐÏ޵ĴúÂëÖ´ÐÐ £¬´Ó¶øµ¼ÖÂÔÚϵͳÉÏÔËÐÐËÁÒâ´úÂë¡£CVSSÆÀ·Ö7.8¡£


0x02 ´ëÖý¨Òé


Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶ £¬²¹¶¡»ñÈ¡Á´½Ó£º

https://www.autodesk.com/trust/security-advisories/adsk-sa-2020-0002


0x03 ÓйØÐÂÎÅ


https://www.securityweek.com/microsoft-out-band-advisory-addresses-autodesk-fbx-vulnerabilities


0x04 ²Î¿¼Á´½Ó


https://www.autodesk.com/trust/security-advisories/adsk-sa-2020-0002

https://nvd.nist.gov/vuln/detail/CVE-2020-7080

https://nvd.nist.gov/vuln/detail/CVE-2020-7081

https://nvd.nist.gov/vuln/detail/CVE-2020-7082

https://nvd.nist.gov/vuln/detail/CVE-2020-7083

https://nvd.nist.gov/vuln/detail/CVE-2020-7084

https://nvd.nist.gov/vuln/detail/CVE-2020-7085


0x05 ¹¦·òÏß


2020-04-15 Autodesk¹Ù·½°ä²¼·ì϶

2020-04-24 VSRC°ä²¼·ì϶¹«¸æ


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾