« Volver al listado

CVE-2009-3577

Estado: ModificadaAlta (9.3)—

Autodesk 3D Studio Max (3DSMax) 6 through 9 and 2008 through 2010 allows remote attackers to execute arbitrary code via a .max file with a MAXScript statement that calls the DOSCommand method, related to "application callbacks."

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2009-3577",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 9.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2009-11-24T17:30:00.327",
  "references": [
    {
      "url": "http://securitytracker.com/id?1023230",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.coresecurity.com/content/3dsmax-arbitrary-command-execution",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/508012/100/0/threaded",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/36634",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://securitytracker.com/id?1023230",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.coresecurity.com/content/3dsmax-arbitrary-command-execution",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/508012/100/0/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/36634",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-94"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Autodesk 3D Studio Max (3DSMax) 6 through 9 and 2008 through 2010 allows remote attackers to execute arbitrary code via a .max file with a MAXScript statement that calls the DOSCommand method, related to \"application callbacks.\""
    },
    {
      "lang": "es",
      "value": "Autodesk 3D Studio Max (3DSMax) v6 hasta v9 y v2008 hasta v2010 permite a atacantes remotos ejecutar código de su elección a través de un archivo .max con una sentencia MAXScript que llama al método DOSCommand, relacionado con \"application callbacks.\"\r\n"
    }
  ],
  "lastModified": "2026-06-16T23:11:56.220",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:autodesk:3ds_max:6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "48A6AC01-DD6A-47DC-A08F-CFF2B00E458A"
            },
            {
              "criteria": "cpe:2.3:a:autodesk:3ds_max:7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "21F34A76-B1BD-45C7-9EFE-221F5E35985F"
            },
            {
              "criteria": "cpe:2.3:a:autodesk:3ds_max:8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9120C1A0-A615-4835-833E-D292813A3362"
            },
            {
              "criteria": "cpe:2.3:a:autodesk:3ds_max:9:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D53212F3-EB04-4AC2-8C18-9FE4C63FBB48"
            },
            {
              "criteria": "cpe:2.3:a:autodesk:3ds_max:2008:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "541F19B1-3E53-4558-BC21-6A14D7567DBE"
            },
            {
              "criteria": "cpe:2.3:a:autodesk:3ds_max:2009:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2CD0EF4E-539D-42CB-B9E7-86A0C8154294"
            },
            {
              "criteria": "cpe:2.3:a:autodesk:3ds_max:2010:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AA2F7BFB-ABB7-4ABA-BCBC-EC507C7C52CB"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}