Lucene search

K
cveAutodeskCVE-2023-25008
HistoryMay 12, 2023 - 9:15 p.m.

CVE-2023-25008

2023-05-1221:15:09
CWE-125
autodesk
web.nvd.nist.gov
22
cve-2023-25008
malicious actor
out-of-bounds read
vulnerability
usd file
code execution
nvd

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

7.6

Confidence

High

EPSS

0.001

Percentile

27.2%

A malicious actor may convince a user to open a malicious USD file that may trigger an out-of-bounds read vulnerability which could result in code execution.

Affected configurations

Nvd
Node
autodesk3ds_max_usdRange0.3
VendorProductVersionCPE
autodesk3ds_max_usd*cpe:2.3:a:autodesk:3ds_max_usd:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "n/a",
    "product": "Autodesk 3ds Max USD Plugin",
    "versions": [
      {
        "version": "0.3",
        "status": "affected"
      }
    ]
  }
]

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

7.6

Confidence

High

EPSS

0.001

Percentile

27.2%

Related for CVE-2023-25008