« Volver al listado

CVE-2022-25793

Estado: ModificadaAlta (7.8)—

A Stack-based Buffer Overflow Vulnerability in Autodesk 3ds Max 2022, 2021, and 2020 may lead to code execution through the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer when parsing ActionScript Byte Code files. This vulnerability may allow arbitrary code execution on affected installations of Autodesk 3ds Max.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-25793",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@autodesk.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "Autodesk 3ds Max",
          "versions": [
            {
              "status": "affected",
              "version": "Autodesk 3ds Max\t2022, 2021, 2020"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-08-10T20:15:31.807",
  "references": [
    {
      "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0006",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@autodesk.com"
    },
    {
      "url": "https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0006",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-1284"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A Stack-based Buffer Overflow Vulnerability in Autodesk 3ds Max 2022, 2021, and 2020 may lead to code execution through the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer when parsing ActionScript Byte Code files. This vulnerability may allow arbitrary code execution on affected installations of Autodesk 3ds Max."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de desbordamiento del búfer en la región Stack de la memoria en Autodesk 3ds Max versiones 2022, 2021 y 2020, puede conllevar a una ejecución de código mediante la falta de comprobación apropiada de la longitud de los datos suministrados por el usuario antes de copiarlos en un búfer en la región stack de la memoria de longitud fija cuando son analizados archivos de código de bytes de ActionScript. Esta vulnerabilidad puede permitir la ejecución de código arbitrario en las instalaciones afectadas de Autodesk 3ds Max"
    }
  ],
  "lastModified": "2026-06-17T04:34:17.447",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:autodesk:3ds_max:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3CB4E3CB-2C64-44C8-ADA7-D88ED4A0C02B",
              "versionEndExcluding": "2020.3.6",
              "versionStartIncluding": "2020"
            },
            {
              "criteria": "cpe:2.3:a:autodesk:3ds_max:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "23E83FC1-97C7-4AD6-806E-6ED14826E82D",
              "versionEndExcluding": "2021.3.10",
              "versionStartIncluding": "2021"
            },
            {
              "criteria": "cpe:2.3:a:autodesk:3ds_max:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E71086D2-9206-46B5-A0F0-C1438C0774B5",
              "versionEndIncluding": "2022.3.3",
              "versionStartIncluding": "2022"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "psirt@autodesk.com"
}