Arbitrary Command Execution in Autodesk 3D Studio Max
CVE-2009-3577

Currently unrated

Key Information:

Vendor

Autodesk

Status
Vendor
CVE Published:
24 November 2009

What is CVE-2009-3577?

A vulnerability exists in Autodesk 3D Studio Max versions 6 to 9 and 2008 to 2010 that allows remote attackers to execute arbitrary code. This can occur through a specially crafted .max file that leverages MAXScript statements to invoke the DOSCommand method. This flaw pertains to how the application handles callbacks, which can be exploited by attackers to perform unauthorized actions on the system.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.