First published: Mon Jul 07 2014(Updated: )
Autodesk VRED Professional 2014 before SR1 SP8 allows remote attackers to execute arbitrary code via Python os library calls in Python API commands to the integrated web server.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Autodesk VRED | =2014 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-2967 is rated as high severity due to its potential to allow remote code execution.
To resolve CVE-2014-2967, users should update Autodesk VRED Professional 2014 to the latest service release.
CVE-2014-2967 affects Autodesk VRED Professional 2014 prior to SR1 SP8.
CVE-2014-2967 is a remote code execution vulnerability due to unsafe Python API commands.
Yes, CVE-2014-2967 can be exploited remotely by attackers using vulnerable Python os library calls.