{"id":"CVE-2026-10710","published":"2026-08-04T13:17:32.507","lastModified":"2026-08-05T05:16:46.030","description":"A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerability in fbxsdk::ExtractDrive. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.","cvssScore":7.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cwes":["CWE-121"],"vendors":[],"products":[],"references":[{"url":"https://www.autodesk.com/products/autodesk-access/overview","tags":[]},{"url":"https://www.autodesk.com/trust/security-advisories/adsk-sa-2026-0010","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw is a stack-based buffer overflow in fbxsdk::ExtractDrive when processing maliciously crafted FBX files, allowing arbitrary code execution. This matters because it can lead to unauthorized access and system compromise.","exploitability":"Exploitation requires the target application to parse a specially crafted FBX file; this is moderately difficult as it depends on user input or specific file handling conditions.","blast_radius":"If exploited, the impact could be severe, leading to full control of the affected system by an attacker.","remediation":"Update to the latest version of Autodesk FBX SDK that addresses this vulnerability.","tags":["rce","file-attack","sdk","fbx"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-08-11T06:51:26.542Z"}}