ZDI-23-584: Autodesk 3DS Max USD File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autodesk 3DS Max. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-584?
ZDI-23-584 has a high severity rating due to its potential for remote code execution.
How do I fix ZDI-23-584?
To fix ZDI-23-584, ensure that Autodesk 3DS Max is updated to the latest version provided by Autodesk.
What are the symptoms of ZDI-23-584 exploitation?
Exploitation of ZDI-23-584 can lead to unexpected crashes, unauthorized code execution, or data corruption within Autodesk 3DS Max.
Who is affected by ZDI-23-584?
ZDI-23-584 affects users of Autodesk 3DS Max who open malicious files or visit harmful web pages.
Is user interaction required to exploit ZDI-23-584?
Yes, user interaction is required as the target must either open a malicious file or visit a malicious webpage for exploitation.