CVE-2022-25793

HIGH

Autodesk 3ds Max < 2020.3.6 - Buffer Overflow

Title source: rule
STIX 2.1

Description

A Stack-based Buffer Overflow Vulnerability in Autodesk 3ds Max 2022, 2021, and 2020 may lead to code execution through the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer when parsing ActionScript Byte Code files. This vulnerability may allow arbitrary code execution on affected installations of Autodesk 3ds Max.

Scores

CVSS v3 7.8
EPSS 0.0006
EPSS Percentile 19.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-1284
Status published
Products (1)
autodesk/3ds_max 2020 - 2020.3.6
Published Aug 10, 2022
Tracked Since Feb 18, 2026