SecPod

Learn Search

Search across all Learn content

← Back to Security Research
Microsoft out-of-band Security Updates for Office and Paint 3D

Microsoft out-of-band Security Updates for Office and Paint 3D

Microsoft released an out-of-band security update addressing multiple vulnerabilities that plug remote code execution vulnerabilities in an Autodesk FBX library incorporated into Microsoft Office, Office 365 ProPlus and Paint 3D applications. A vulnerability management tool can detect multiple vulne...

Apr 22, 2020By Jithendra R3 min read

Microsoft released an out-of-band security update addressing multiple vulnerabilities that plug remote code execution vulnerabilities in an Autodesk FBX library incorporated into Microsoft Office, Office 365 ProPlus and Paint 3D applications. A vulnerability management tool can detect multiple vulnerabilities.

Though the updates for these vulnerabilities are rated “Important” in severity, they allow remote code execution on affected products. Tracking the vulnerabilities as CVE-2020-7080, CVE-2020-7081, CVE-2020-7082, CVE-2020-7083, CVE-2020-7084, and CVE-2020-7085. All these vulnerabilities can be patched using a patch management tool.

According to Microsoft’s Tuesday advisory. “Remote code execution vulnerabilities exist in Microsoft products that utilize the FBX library when processing specially crafted 3D content”.

Following are the details of the vulnerabilities in autodesk fbx library :

1) CVE-2020-7080: A buffer overflow vulnerability exists in the Autodesk FBX-SDK versions 2019.0 and earlier that might lead to arbitrary code execution. For successful exploitation of the vulnerability, an attacker could trick a user into opening a malevolent FBX file. Resulting in exploiting a buffer overflow vulnerability in FBX’s SDK allowing to run arbitrary code on the affected system.

2) CVE-2020-7081: A type confusion vulnerability exists in the Autodesk FBX-SDK versions 2019.0 and earlier that might lead to arbitrary code execution. For successful exploitation of the vulnerability, an attacker could lure a user to open a malevolent FBX file. Resulting in exploitation of type confusion vulnerability in FBX’s SDK, letting an attacker to read/write out-of-bounds memory location,  run arbitrary code on the affected system or leading to a denial of service (DoS).

3) CVE-2020-7082: A use-after-free vulnerability exists in the Autodesk FBX-SDK versions 2019.0 and earlier that might lead to remote code execution. For successful exploitation of the vulnerability, an attacker could persuade a user to open a maliciously crafted FBX file. Resulting in exploitation of the use-after-free vulnerability in FBX’s SDK. Allowing an application to reference a memory location which an unauthorized third party controls. Letting an attacker run arbitrary code on the compromised system.

More Details:

4) CVE-2020-7083: An integer overflow vulnerability exists in the Autodesk FBX-SDK versions 2019.0 and earlier that might lead to denial of service(DoS) of the application. For successful exploitation of the vulnerability, an attacker could trick a user to open a noxiously crafted FBX file. Resulting in exploitation of an integer overflow vulnerability in FBX’s SDK leading to denial of service(DoS).

5) CVE-2020-7084: A NULL pointer dereference vulnerability exists in the Autodesk FBX-SDK versions 2019.0 and earlier. That might lead to denial of service(DoS) of the application. For successful exploitation of the vulnerability, an attacker could lure a user into opening a noxious FBX file. Resulting in the exploitation of a Null Pointer Dereference vulnerability in FBX’s SDK causing a denial of service(DoS).

6) CVE-2020-7085: A heap overflow vulnerability exists in the Autodesk FBX-SDK versions 2019.2 and earlier may lead to arbitrary code execution. For successful exploitation of the vulnerability, an attacker could lure the user into opening a maliciously crafted FBX file resulting in the exploitation of the heap overflow vulnerability and gain limited code execution by altering certain values in an FBX file, granting an attacker to run arbitrary code on the compromised system.

Affected Products

  • Microsoft Office 2016
  • Microsoft Office 2019
  • Office 365 ProPlus
  • Paint 3D

Solution

Microsoft has released a security advisory to fix these vulnerabilities.

SanerNow security content has been published to detect this vulnerability. We strongly recommend installing these security updates without any delay.

Featured Posts

Open Operation CameraSwarm: Inside the Toolkit Behind 14,530 Compromised Dahua Cameras
Operation CameraSwarm: Inside the Toolkit Behind 14,530 Compromised Dahua Cameras

CVE Research

Operation CameraSwarm: Inside the Toolkit Behind 14,530 Compromised Dahua Cameras

A single operator compromised 14,530+ Dahua cameras across Ukraine and Russia in 35 days, chaining credential brute-force, a CVE-2021-33044/33045 authentication bypass, and P2P relay abuse to plant a persistent backdoor and harvest transferable admin access.

Aug 21, 2026

Open Critical GitLab Flaw Exposes Public Projects to Deletion — Two CVEs Patched, Including High-Severity CSRF
Critical GitLab Flaw Exposes Public Projects to Deletion — Two CVEs Patched, Including High-Severity CSRF

CVE Research

Critical GitLab Flaw Exposes Public Projects to Deletion — Two CVEs Patched, Including High-Severity CSRF

CVE-2026-19478 is a critical code injection vulnerability in GitLab CE/EE that allows an unauthenticated attacker to modify or delete public projects and user data by abusing a GraphQL directive. A second high-severity issue, CVE-2026-19650, involves cross-site request forgery in the GraphQL multiplex query handler. This article examines how the critical vulnerability works, the availability of a public proof-of-concept, the potential impact on self-managed instances, the affected versions, and the security updates released to remediate both issues.

Aug 19, 2026

Open No Password Needed: macOS Screen Sharing Flaw (CVE-2026-65400) Used to Deploy Monero Miners
No Password Needed: macOS Screen Sharing Flaw (CVE-2026-65400) Used to Deploy Monero Miners

CVE Research

No Password Needed: macOS Screen Sharing Flaw (CVE-2026-65400) Used to Deploy Monero Miners

Aug 19, 2026

Open Evooo1Bot: Mirai-Based Linux Botnet Turns Edge Devices Into SOCKS5 Proxies
Evooo1Bot: Mirai-Based Linux Botnet Turns Edge Devices Into SOCKS5 Proxies

CVE Research

Evooo1Bot: Mirai-Based Linux Botnet Turns Edge Devices Into SOCKS5 Proxies

Aug 19, 2026