Microsoft issued an out-of-band updateto patch vulnerabilities for a variety of company products that use the C++ software development platform and API toolkit Autodesk FBX library.

The important-rated vulnerabilities are covered by CVE-2020-7080, CVE-2020-7081, CVE-2020-7082, CVE-2020-7083, CVE-2020-7084 and CVE-2020-7085.

These can lead to remote code execution if exploited which can be done if it processes specially crafted 3D content that was created by the attacker. A successful attack could gain the same user rights as the local user, however, users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights, Microsoft wrote.

The products affected are the 32- and 64-bit editions of Microsoft 2019, Office 365 ProPlus and Paint 3D.





Patches are available here.