← Vulnerability feed

Vulnerability record · CVE-2021-27030 · published 19 April 2021

CVE-2021-27030: Autodesk FBX Review path traversal leads to code execution

Autodesk · Fbx Review

FBX Review fails to properly validate paths inside FBX files, allowing a crafted file to traverse directories and execute arbitrary code. Because the file is opened through the normal review workflow, a user can be tricked into triggering it, making it a realistic client-side attack against design workstations.

7.8 CVSS 3.1 High EPSS 60% · top 0.9% CWE-22 · Path traversal
7.8CVSS 3.1 base score, v2 9.3
60%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

A user may be tricked into opening a malicious FBX file which may exploit a Directory Traversal Remote Code Execution vulnerability in FBX’s Review causing it to run arbitrary code on the system.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityCVSS 7.8 with high confidentiality, integrity and availability impact and a very high EPSS score, but exploitation requires user interaction and no KEV listing or public exploit is confirmed.

What it is

FBX Review fails to properly validate paths inside FBX files, allowing a crafted file to traverse directories and execute arbitrary code. Because the file is opened through the normal review workflow, a user can be tricked into triggering it, making it a realistic client-side attack against design workstations.

Impact

An attacker who gets a victim to open a malicious FBX file can run arbitrary code with the victim's privileges, leading to full compromise of confidentiality, integrity and availability on that host.

Attack surface

Reached locally by opening a malicious FBX file in FBX Review; the CVSS vector shows no privileges required but user interaction is required, so the victim must open the file.

Exploitation

Not listed in CISA KEV and no public exploit tag is present in the references, though EPSS is high at 0.5964 (99th percentile), indicating elevated likelihood of attempted exploitation.

What to do

  • Update FBX Review to the fixed version referenced in Autodesk advisory adsk-sa-2021-0001.
  • Block or quarantine untrusted FBX files at email and web gateways before they reach design workstations.
  • Restrict execution of FBX Review to trusted sources and avoid opening files from unknown senders.
  • Run FBX Review with least privilege so a successful exploit cannot gain administrative rights.

Detection

  • Monitor for FBX Review spawning unexpected child processes such as cmd.exe, powershell.exe or scripting hosts.
  • Alert on file writes or reads outside expected project directories by FBX Review processes.
  • Track FBX files received from external senders and correlate with FBX Review execution events.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-27030 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2024-23139Autodesk fbx review out-of-bounds write vulnerabilityA maliciously crafted ABC file, when parsed through Autodesk FBX, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this…EPSS 0.45%7.8CVE-2022-25794Autodesk fbx review out-of-bounds read vulnerabilityAn Out-Of-Bounds Read Vulnerability in Autodesk FBX Review version 1.5.2 and prior may lead to code execution through maliciously crafted ActionScrip…EPSS 1.2%7.8CVE-2021-27044Autodesk fbx review out-of-bounds read vulnerabilityA Out-Of-Bounds Read/Write Vulnerability in Autodesk FBX Review version 1.4.0 may lead to remote code execution through maliciously crafted DLL files…EPSS 1.2%7.8CVE-2021-40157Autodesk fbx review memory buffer overflow vulnerabilityA user may be tricked into opening a malicious FBX file which may exploit an Untrusted Pointer Dereference vulnerability in FBX’s Review version 1.5.…EPSS 0.76%7.8CVE-2021-27028Autodesk fbx review out-of-bounds write vulnerabilityA Memory Corruption Vulnerability in Autodesk FBX Review version 1.5.0 and prior may lead to remote code execution through maliciously crafted DLL fi…EPSS 2.3%7.8CVE-2021-27031Autodesk fbx review use after free vulnerabilityA user may be tricked into opening a malicious FBX file which may exploit a use-after-free vulnerability in FBX's Review causing the application to r…EPSS 1.4%7.8CVE-2021-27027Autodesk fbx review out-of-bounds read vulnerabilityAn Out-Of-Bounds Read Vulnerability in Autodesk FBX Review version 1.5.0 and prior may lead to code execution through maliciously crafted DLL files o…EPSS 1.8%5.5CVE-2021-27029Autodesk fbx review null pointer dereference vulnerabilityThe user may be tricked into opening a malicious FBX file which may exploit a Null Pointer Dereference vulnerability in FBX's Review version 1.5.0 an…EPSS 0.78%

Source: NIST National Vulnerability Database (record CVE-2021-27030), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.