Finding CVE-2020-1321: Fuzzing Office's 3D Model Parser
Vulnerability research - CVE-2020-1321 · Public / PatchedA grammar-driven .glb fuzzing campaign found a memory-corruption bug in the shared 3D parser used by Microsoft Word and the Microsoft 3D Viewer. Reported to MSRC in January 2020; patched on June 9, 2020 as the Microsoft Office Remote Code Execution Vulnerability (CWE-119, CVSS 7.8, Exploitation Less Likely).