First published: Mon Apr 17 2023(Updated: )
A malicious actor may convince a victim to open a malicious USD file that may trigger an out-of-bounds write vulnerability which may result in code execution.
Credit: psirt@autodesk.com
Affected Software | Affected Version | How to fix |
---|---|---|
Autodesk Maya Usd | <0.23.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-27907 is a vulnerability that allows a malicious actor to execute arbitrary code by tricking a victim into opening a malicious USD file.
Autodesk Maya USD version 0.23.0 and earlier are affected by CVE-2023-27907.
CVE-2023-27907 has a severity rating of 7.8 (High).
To fix CVE-2023-27907, update Autodesk Maya USD to a version later than 0.23.0.
You can find more information about CVE-2023-27907 in the Autodesk Security Advisories: [https://www.autodesk.com/trust/security-advisories/adsk-sa-2023-0003](https://www.autodesk.com/trust/security-advisories/adsk-sa-2023-0003)