{"id":"CVE-2026-10709","published":"2026-08-04T13:17:32.377","lastModified":"2026-08-05T05:16:45.593","description":"A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerability in fbxsdk::FbxIO::BinaryReadSectionHeader. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.","cvssScore":7.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cwes":["CWE-121"],"vendors":[],"products":[],"references":[{"url":"https://www.autodesk.com/products/autodesk-access/overview","tags":[]},{"url":"https://www.autodesk.com/trust/security-advisories/adsk-sa-2026-0010","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"This flaw involves a stack-based buffer overflow in the parsing of FBX files using Autodesk's FBX SDK, allowing arbitrary code execution.","exploitability":"Exploitation requires a maliciously crafted FBX file and access to parse it through the affected SDK; this is moderately difficult due to the need for specific input.","blast_radius":"If exploited, this vulnerability could lead to full compromise of systems using the affected software, including data theft or system control.","remediation":"Update to the latest version of Autodesk FBX SDK that addresses this vulnerability.","tags":["rce","file-format","sdk","autodesk"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-08-11T06:51:20.239Z"}}