ZDI-23-585: Autodesk 3DS Max SKP File Parsing Use-After-Free Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autodesk 3DS Max. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-585?
The severity of ZDI-23-585 is considered critical due to its potential for remote code execution.
How do I fix ZDI-23-585?
To fix ZDI-23-585, update Autodesk 3DS Max to the latest version that addresses this vulnerability.
Who is affected by ZDI-23-585?
Users of Autodesk 3DS Max are affected by ZDI-23-585 if they have not updated their software to the latest version.
What type of attack uses ZDI-23-585?
ZDI-23-585 can be exploited through remote code execution techniques requiring user interaction with malicious files or websites.
Is user interaction required for ZDI-23-585?
Yes, user interaction is required for ZDI-23-585 as the target must visit a malicious page or open a malicious file.