First published: Tue Nov 24 2009(Updated: )
Autodesk Softimage 7.x and Softimage XSI 6.x allow remote attackers to execute arbitrary JavaScript code via a scene package containing a Scene Table of Contents (aka .scntoc) file with a Script_Content element, as demonstrated by code that loads the WScript.Shell ActiveX control.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Autodesk Softimage | =6.0 | |
Autodesk Softimage | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-3576 has a high severity rating due to its potential for remote code execution.
To fix CVE-2009-3576, users should update to a patched version of Autodesk Softimage that resolves this vulnerability.
CVE-2009-3576 affects Autodesk Softimage versions 6.x and 7.x.
CVE-2009-3576 can be exploited by remote attackers who utilize a vulnerable .scntoc file.
CVE-2009-3576 can facilitate arbitrary JavaScript code execution leading to potential compromise of the system.