Vulnerability Details CVE-2009-3577
Autodesk 3D Studio Max (3DSMax) 6 through 9 and 2008 through 2010 allows remote attackers to execute arbitrary code via a .max file with a MAXScript statement that calls the DOSCommand method, related to "application callbacks."
Exploit prediction scoring system (EPSS) score
EPSS Score 0.04
EPSS Ranking 87.9%
CVSS Severity
CVSS v2 Score 9.3
Products affected by CVE-2009-3577
-
cpe:2.3:a:autodesk:3ds_max:2008
-
cpe:2.3:a:autodesk:3ds_max:2009
-
cpe:2.3:a:autodesk:3ds_max:2010
-
cpe:2.3:a:autodesk:3ds_max:6
-
cpe:2.3:a:autodesk:3ds_max:7
-
cpe:2.3:a:autodesk:3ds_max:8
-
cpe:2.3:a:autodesk:3ds_max:9