CVE Feed

    Dashboard / CVE / CVE-2024-20677

    CVE-2024-20677

    A security vulnerability exists in FBX that could lead to remote code execution. To mitigate this vulnerability, the ability to insert FBX files has been disabled in Word, Excel, PowerPoint and Outlook for Windows and Mac. Versions of Office that had this feature enabled will no longer have access to it. This includes Office 2019, Office 2021, Office LTSC for Mac 2021, and Microsoft 365. As of February 13, 2024, the ability to insert FBX files has also been disabled in 3D Viewer. 3D models in Office documents that were previously inserted from a FBX file will continue to work as expected unless the Link to File option was chosen at insert time. This change is effective as of the January 9, 2024 security update.

    Published:Jan 9, 2024
    Last Modified:May 3, 2025
    EPS:Jan 9, 2024
    EPSS Score:0.00392
    CVSS Score:7.8

    Affected Products

    Vendor
    Microsoft
    Product
    365 Apps
    Vendor
    Microsoft
    Product
    Office
    Vendor
    Microsoft
    Product
    Office Long Term Servicing Channel

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High