First published: Fri May 12 2023(Updated: )
A malicious actor may convince a user to open a malicious USD file that may trigger an out-of-bounds read vulnerability which could result in code execution.
Credit: psirt@autodesk.com psirt@autodesk.com
Affected Software | Affected Version | How to fix |
---|---|---|
Autodesk 3ds Max | <=0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-25008 is a vulnerability that allows a malicious actor to exploit an out-of-bounds read vulnerability when a user opens a malicious USD file, potentially leading to code execution.
The Autodesk 3ds Max USD version 0.3 is affected by CVE-2023-25008.
A user can be affected by CVE-2023-25008 if they open a malicious USD file created by a malicious actor.
CVE-2023-25008 has a severity rating of 7.8 (high).
To mitigate CVE-2023-25008, users should update Autodesk 3ds Max USD to a version that is not affected by the vulnerability.