CVE-2009-3576

Autodesk Softimage - Code Injection

Title source: rule

Description

Autodesk Softimage 7.x and Softimage XSI 6.x allow remote attackers to execute arbitrary JavaScript code via a scene package containing a Scene Table of Contents (aka .scntoc) file with a Script_Content element, as demonstrated by code that loads the WScript.Shell ActiveX control.

Exploits (2)

exploitdb WRITEUP VERIFIED
by Core Security · textlocalwindows
https://www.exploit-db.com/exploits/10211
exploitdb WORKING POC VERIFIED
by Diego Juarez · remotewindows
https://www.exploit-db.com/exploits/33273

Scores

EPSS 0.0496
EPSS Percentile 89.5%

Classification

CWE
CWE-94
Status draft

Affected Products (2)

autodesk/autodesk_softimage
autodesk/autodesk_softimage_xsi

Timeline

Published Nov 24, 2009
Tracked Since Feb 18, 2026