Vulnerability record · CVE-2021-27030 · published 19 April 2021
CVE-2021-27030: Autodesk FBX Review path traversal leads to code execution
Autodesk · Fbx Review
FBX Review fails to properly validate paths inside FBX files, allowing a crafted file to traverse directories and execute arbitrary code. Because the file is opened through the normal review workflow, a user can be tricked into triggering it, making it a realistic client-side attack against design workstations.
Description
A user may be tricked into opening a malicious FBX file which may exploit a Directory Traversal Remote Code Execution vulnerability in FBX’s Review causing it to run arbitrary code on the system.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 7.8 with high confidentiality, integrity and availability impact and a very high EPSS score, but exploitation requires user interaction and no KEV listing or public exploit is confirmed.
What it is
FBX Review fails to properly validate paths inside FBX files, allowing a crafted file to traverse directories and execute arbitrary code. Because the file is opened through the normal review workflow, a user can be tricked into triggering it, making it a realistic client-side attack against design workstations.
Impact
An attacker who gets a victim to open a malicious FBX file can run arbitrary code with the victim's privileges, leading to full compromise of confidentiality, integrity and availability on that host.
Attack surface
Reached locally by opening a malicious FBX file in FBX Review; the CVSS vector shows no privileges required but user interaction is required, so the victim must open the file.
Exploitation
Not listed in CISA KEV and no public exploit tag is present in the references, though EPSS is high at 0.5964 (99th percentile), indicating elevated likelihood of attempted exploitation.
What to do
- Update FBX Review to the fixed version referenced in Autodesk advisory adsk-sa-2021-0001.
- Block or quarantine untrusted FBX files at email and web gateways before they reach design workstations.
- Restrict execution of FBX Review to trusted sources and avoid opening files from unknown senders.
- Run FBX Review with least privilege so a successful exploit cannot gain administrative rights.
Detection
- Monitor for FBX Review spawning unexpected child processes such as cmd.exe, powershell.exe or scripting hosts.
- Alert on file writes or reads outside expected project directories by FBX Review processes.
- Track FBX files received from external senders and correlate with FBX Review execution events.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.autodesk.com/trust/security-advisories/adsk-sa-2021-0001 | Vendor Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-21-1070/ | Third Party AdvisoryVDB Entry |
| https://www.zerodayinitiative.com/advisories/ZDI-21-466/ | Third Party AdvisoryVDB Entry |
| https://www.autodesk.com/trust/security-advisories/adsk-sa-2021-0001 | Vendor Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-21-1070/ | Third Party AdvisoryVDB Entry |
| https://www.zerodayinitiative.com/advisories/ZDI-21-466/ | Third Party AdvisoryVDB Entry |
Track CVE-2021-27030 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-27030), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.