CVE-2023-25008: High severity autodesk 3ds max vulnerability
Published May 12, 2023
·Updated
A malicious actor may convince a user to open a malicious USD file that may trigger an out-of-bounds read vulnerability which could result in code execution.
Affected Software
1 affected component
Autodesk 3ds Max Usd<=0.3
Event History
May 12, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2023-25008?
CVE-2023-25008 is a vulnerability that allows a malicious actor to exploit an out-of-bounds read vulnerability when a user opens a malicious USD file, potentially leading to code execution.
2
What software is affected by CVE-2023-25008?
The Autodesk 3ds Max USD version 0.3 is affected by CVE-2023-25008.
3
How can a user be affected by CVE-2023-25008?
A user can be affected by CVE-2023-25008 if they open a malicious USD file created by a malicious actor.
4
What is the severity of CVE-2023-25008?
CVE-2023-25008 has a severity rating of 7.8 (high).
5
How can CVE-2023-25008 be mitigated?
To mitigate CVE-2023-25008, users should update Autodesk 3ds Max USD to a version that is not affected by the vulnerability.