Autodesk 3ds Max Application Callbacks Arbitrary Command Execution Vulnerability
BID:36634
Info
Autodesk 3ds Max Application Callbacks Arbitrary Command Execution Vulnerability
| Bugtraq ID: | 36634 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-3577 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 23 2009 12:00AM |
| Updated: | Dec 02 2009 05:55PM |
| Credit: | Sebastian Tello from Core Security Technologies |
| Vulnerable: |
Autodesk 3ds Max 2010 0 Autodesk 3ds Max 2009 0 Autodesk 3ds Max 2008 0 Autodesk 3ds Max 9 Autodesk 3ds Max 8 Autodesk 3ds Max 7 Autodesk 3ds Max 6 |
| Not Vulnerable: | |
Discussion
Autodesk 3ds Max Application Callbacks Arbitrary Command Execution Vulnerability
Autodesk 3ds Max is prone to a vulnerability that lets attackers execute arbitrary commands in the context of the vulnerable application.
This issue affects the following:
3ds Max 6 through 9
3ds Max 2008 through 2010
Other versions may also be vulnerable.
Autodesk 3ds Max is prone to a vulnerability that lets attackers execute arbitrary commands in the context of the vulnerable application.
This issue affects the following:
3ds Max 6 through 9
3ds Max 2008 through 2010
Other versions may also be vulnerable.
Exploit / POC
Autodesk 3ds Max Application Callbacks Arbitrary Command Execution Vulnerability
The following proof-of-concept code is available:
callbacks.addScript #filePostOpen ("DOSCommand(\"calc.exe\")") id:#mbLoadCallback persistent:true
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following proof-of-concept code is available:
callbacks.addScript #filePostOpen ("DOSCommand(\"calc.exe\")") id:#mbLoadCallback persistent:true
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Autodesk 3ds Max Application Callbacks Arbitrary Command Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Autodesk 3ds Max Application Callbacks Arbitrary Command Execution Vulnerability
References:
References:
- Autodesk Homepage (Autodesk)
- CORE-2009-0909: Autodesk 3DS Max Application Callbacks Arbitrary Command Executi (CORE Security Technologies Advisories
)