ZDI-23-575: Autodesk 3DS Max SKP File Parsing Use-After-Free Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autodesk 3DS Max. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-575?
The severity of ZDI-23-575 is considered critical due to its ability to allow remote code execution.
How do I fix ZDI-23-575?
To fix ZDI-23-575, ensure you apply the latest security updates provided by Autodesk for 3DS Max.
What does ZDI-23-575 affect?
ZDI-23-575 affects Autodesk 3DS Max installations that have not been updated to mitigate the vulnerability.
What are the exploitation requirements for ZDI-23-575?
Exploitation of ZDI-23-575 requires user interaction, as the target must open a malicious file or visit a malicious webpage.
Can ZDI-23-575 lead to data loss?
Yes, successful exploitation of ZDI-23-575 can potentially lead to data loss or system compromise through arbitrary code execution.