CVE-2009-3576

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
24/11/2009
Last modified:
09/04/2025

Description

Autodesk Softimage 7.x and Softimage XSI 6.x allow remote attackers to execute arbitrary JavaScript code via a scene package containing a Scene Table of Contents (aka .scntoc) file with a Script_Content element, as demonstrated by code that loads the WScript.Shell ActiveX control.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:autodesk:autodesk_softimage:7.0:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:autodesk_softimage_xsi:6.0:*:*:*:*:*:*:*