← Vulnerability feed

Vulnerability record · CVE-2021-27031 · published 19 April 2021

CVE-2021-27031: Autodesk fbx review use after free vulnerability

Autodesk · Fbx Review

A user may be tricked into opening a malicious FBX file which may exploit a use-after-free vulnerability in FBX's Review causing the application to reference a memory location controlled by an unauthorized third party, thereby running arbitrary code on the system.

7.8 CVSS 3.1 High EPSS 1.4% · top 29.0% CWE-416 · Use after free
7.8CVSS 3.1 base score, v2 9.3
1.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

A user may be tricked into opening a malicious FBX file which may exploit a use-after-free vulnerability in FBX's Review causing the application to reference a memory location controlled by an unauthorized third party, thereby running arbitrary code on the system.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-27031 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2024-23139Autodesk fbx review out-of-bounds write vulnerabilityA maliciously crafted ABC file, when parsed through Autodesk FBX, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this…EPSS 0.45%7.8CVE-2022-25794Autodesk fbx review out-of-bounds read vulnerabilityAn Out-Of-Bounds Read Vulnerability in Autodesk FBX Review version 1.5.2 and prior may lead to code execution through maliciously crafted ActionScrip…EPSS 1.2%7.8CVE-2021-27044Autodesk fbx review out-of-bounds read vulnerabilityA Out-Of-Bounds Read/Write Vulnerability in Autodesk FBX Review version 1.4.0 may lead to remote code execution through maliciously crafted DLL files…EPSS 1.2%7.8CVE-2021-40157Autodesk fbx review memory buffer overflow vulnerabilityA user may be tricked into opening a malicious FBX file which may exploit an Untrusted Pointer Dereference vulnerability in FBX’s Review version 1.5.…EPSS 0.76%7.8CVE-2021-27028Autodesk fbx review out-of-bounds write vulnerabilityA Memory Corruption Vulnerability in Autodesk FBX Review version 1.5.0 and prior may lead to remote code execution through maliciously crafted DLL fi…EPSS 2.3%7.8CVE-2021-27030Autodesk FBX Review path traversal leads to code executionFBX Review fails to properly validate paths inside FBX files, allowing a crafted file to traverse directories and execute arbitrary code. Because the…EPSS 60%analysed7.8CVE-2021-27027Autodesk fbx review out-of-bounds read vulnerabilityAn Out-Of-Bounds Read Vulnerability in Autodesk FBX Review version 1.5.0 and prior may lead to code execution through maliciously crafted DLL files o…EPSS 1.8%5.5CVE-2021-27029Autodesk fbx review null pointer dereference vulnerabilityThe user may be tricked into opening a malicious FBX file which may exploit a Null Pointer Dereference vulnerability in FBX's Review version 1.5.0 an…EPSS 0.78%

Source: NIST National Vulnerability Database (record CVE-2021-27031), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.