CVE-2009-3576: Code Injection
Published Nov 24, 2009
·Updated
Autodesk Softimage 7.x and Softimage XSI 6.x allow remote attackers to execute arbitrary JavaScript code via a scene package containing a Scene Table of Contents (aka .scntoc) file with a ScriptContent element, as demonstrated by code that loads the WScript.Shell ActiveX control.
Affected Software
2 affected components
Autodesk Autodesk Softimage=7.0
Autodesk Autodesk Softimage Xsi=6.0
Event History
Nov 24, 2009
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-3576?
CVE-2009-3576 has a high severity rating due to its potential for remote code execution.
2
How do I fix CVE-2009-3576?
To fix CVE-2009-3576, users should update to a patched version of Autodesk Softimage that resolves this vulnerability.
3
What specific versions are affected by CVE-2009-3576?
CVE-2009-3576 affects Autodesk Softimage versions 6.x and 7.x.
4
Who can exploit CVE-2009-3576?
CVE-2009-3576 can be exploited by remote attackers who utilize a vulnerable .scntoc file.
5
What kind of attacks can CVE-2009-3576 facilitate?
CVE-2009-3576 can facilitate arbitrary JavaScript code execution leading to potential compromise of the system.