Lucene search

K
cve[email protected]CVE-2022-42947
HistoryDec 19, 2022 - 4:15 p.m.

CVE-2022-42947

2022-12-1916:15:11
CWE-787
web.nvd.nist.gov
26
cve-2022-42947
buffer overflow
autodesk maya
arbitrary code execution
nvd

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

32.7%

A maliciously crafted X_B file when parsed through Autodesk Maya 2023 and 2022 can be used to write beyond the allocated buffer. This vulnerability can lead to arbitrary code execution.

Affected configurations

NVD
Node
autodeskmayaMatch2023
CPENameOperatorVersion
autodesk:mayaautodesk mayaeq2023

CNA Affected

[
  {
    "vendor": "n/a",
    "product": "Autodesk Maya",
    "versions": [
      {
        "version": "2023, 2022",
        "status": "affected"
      }
    ]
  }
]

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

32.7%

Related for CVE-2022-42947