CVE-2022-25793
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/08/2022
Last modified:
08/08/2023
Description
A Stack-based Buffer Overflow Vulnerability in Autodesk 3ds Max 2022, 2021, and 2020 may lead to code execution through the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer when parsing ActionScript Byte Code files. This vulnerability may allow arbitrary code execution on affected installations of Autodesk 3ds Max.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:autodesk:3ds_max:*:*:*:*:*:*:*:* | 2020 (including) | 2020.3.6 (excluding) |
| cpe:2.3:a:autodesk:3ds_max:*:*:*:*:*:*:*:* | 2021 (including) | 2021.3.10 (excluding) |
| cpe:2.3:a:autodesk:3ds_max:*:*:*:*:*:*:*:* | 2022 (including) | 2022.3.3 (including) |
To consult the complete list of CPE names with products and versions, see this page



