// For flags

CVE-2009-3576

Autodesk SoftImage Scene TOC - Arbitrary Command Execution

Severity Score

9.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

3
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Autodesk Softimage 7.x and Softimage XSI 6.x allow remote attackers to execute arbitrary JavaScript code via a scene package containing a Scene Table of Contents (aka .scntoc) file with a Script_Content element, as demonstrated by code that loads the WScript.Shell ActiveX control.

Autodesk Softimage v7.x y Softimage XSI v6.x permite a atacantes remotos ejecutar código JavaScript de su elección a través de un paquete de escena que contiene un archivo Tabla de Contenidos de Escena (como .scntoc) con un elemento Script_Content, como queda demostrado por el código que carga el control ActiveX WScript.Shell.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2009-10-07 CVE Reserved
  • 2009-11-23 First Exploit
  • 2009-11-24 CVE Published
  • 2024-08-07 CVE Updated
  • 2025-04-17 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-94: Improper Control of Generation of Code ('Code Injection')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Autodesk
Search vendor "Autodesk"
Autodesk Softimage
Search vendor "Autodesk" for product "Autodesk Softimage"
7.0
Search vendor "Autodesk" for product "Autodesk Softimage" and version "7.0"
-
Affected
Autodesk
Search vendor "Autodesk"
Autodesk Softimage Xsi
Search vendor "Autodesk" for product "Autodesk Softimage Xsi"
6.0
Search vendor "Autodesk" for product "Autodesk Softimage Xsi" and version "6.0"
-
Affected