Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

Tenable 部落格

訂閱

ADV200004: Microsoft 發佈頻外公告,公開了 Autodesk Filmbox (FBX) Library 中的錯誤。

Microsoft responds to a recent security advisory from Autodesk by publishing an out-of-band advisory for Office products integrating the Autodesk library.

背景說明

On April 15, Autodesk released a security advisory, ADSK-SA-2020-0002, to address six vulnerabilities in the Autodesk Filmbox (FBX) Software Development Kit, which “allows application and content vendors to transfer existing content into the FBX format with minimal effort.”

In response to Autodesk’s advisory, Microsoft issued an out-of-band advisory, ADV200004, on April 21, as the FBX library is integrated into specific versions of Microsoft Office, Office 365 ProPlus and Paint 3D.

分析

In ADSK-SA-2020-0002, Autodesk patched the following six vulnerabilities:

CVE 弱點 Impact CVSSv3.x*
CVE-2020-7080 Buffer Overflow 任意程式碼執行 7.8
CVE-2020-7081 類型混淆 任意程式碼執行,拒絕服務
CVE-2020-7082 釋放後使用 任意程式碼執行
CVE-2020-7083 整數溢位 Denial of Service
CVE-2020-7084 Null 指標取值 Denial of Service 5.5
CVE-2020-7085 堆積緩衝區溢位 任意程式碼執行 7.8

*Please note that the CVSSv3.x scores referenced in the table above were available at the time this blog post was published and may be subject to change.

Though not all the vulnerabilities had CVSSv3.x scores assigned in their U.S. National Vulnerability Database entries, Autodesk collectively rated their advisory as High.

Exploitation of these vulnerabilities requires an attacker to convince their victim to open a malicious Microsoft Office, Office 365 ProPlus or Paint 3D file that contains specially crafted 3D content which takes advantage of the vulnerabilities in the FBX library.

概念驗證

F-Secure researcher Max Van Amerongen, credited with the discovery of CVE-2020-7085, has tweeted a proof-of-concept video demonstrating the heap overflow vulnerability:

解決方法

Microsoft’s advisory states that it has addressed these vulnerabilities in the following products:

產品 Version 知識庫文章
Microsoft Office 2016 隨選即用 32 位元和 64 位元版本 Office 2016 C2R
Microsoft Office 2019 32 位元和 64 位元版本 Office 2019
Office 365 專業增強版 32 位元和 64 位元版本 Office 365 專業增強版
小畫家 3D 小畫家 3D 版本資訊

However, at the time this blog post was published, there were no new updates to the articles listed above. The last time these articles were updated was on April 14, which coincided with April’s Patch Tuesday release. It is unclear if Microsoft plans to release its updates as part of this out-of-band release, or if the fixes will be included as part of May’s Patch Tuesday release.

Since FBX is an included library in these versions of Office and Paint 3D and Microsoft released an out-of-band advisory for these flaws, we strongly encourage organizations to apply these patches as soon as they are available.

找出受影響的系統

A list of Tenable plugins to identify these vulnerabilities will appear here as they’re released.

取得更多資訊

加入 Tenable Community 的 Tenable 安全回應團隊

深入瞭解 Tenable,這是用於全面管理新型攻擊破綻的首創 Cyber Exposure 平台。

索取 Tenable.io Vulnerability Management 的 30 天免費試用

相關文章

您可以利用的網路安全最新消息

輸入您的電子郵件,就不會錯過來自 Tenable 專家提供的及時警示與安全指引。