ZDI-23-574: Autodesk 3DS Max SKP File Parsing Use-After-Free Information Disclosure Vulnerability
Published May 12, 2023
·Updated
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Autodesk 3DS Max. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
Affected Software
1 affected component
Autodesk 3ds Max
Event History
May 12, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-23-574?
ZDI-23-574 is classified as a moderate severity vulnerability due to its potential to disclose sensitive information.
2
How do I fix ZDI-23-574?
To mitigate ZDI-23-574, ensure that you apply the latest patches and updates provided by Autodesk for 3DS Max.
3
What software is affected by ZDI-23-574?
ZDI-23-574 specifically affects Autodesk 3DS Max installations.
4
What type of attack does ZDI-23-574 involve?
ZDI-23-574 involves a remote attack that requires user interaction to exploit.
5
What user action is needed to exploit ZDI-23-574?
To exploit ZDI-23-574, the user must either visit a malicious webpage or open a malicious file.