PT-2022-26673 · Autodesk · Autodesk Maya

Published

2022-12-19

·

Updated

2023-04-17

·

CVE-2022-42946

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Autodesk Maya versions 2022 through 2023
Description Parsing a maliciously crafted X B and PRT file can force Autodesk Maya to read beyond allocated buffer. This issue, in conjunction with other vulnerabilities, could lead to code execution in the context of the current process.
Recommendations For Autodesk Maya version 2022, update to a version that includes a fix for this issue. For Autodesk Maya version 2023, update to a version that includes a fix for this issue. As a temporary workaround, consider restricting the parsing of X B and PRT files to minimize the risk of exploitation.

Fix

Out of bounds Read

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2022-42946
ZDI-23-099
ZDI-23-101
ZDI-23-102
ZDI-23-103
ZDI-23-104

Affected Products

Autodesk Maya