CVE-2022-42946

Parsing a maliciously crafted X_B and PRT file can force Autodesk Maya 2023 and 2022 to read beyond allocated buffer. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
Configurations

Configuration 1 (hide)

cpe:2.3:a:autodesk:maya:2023:*:*:*:*:*:*:*

History

17 Apr 2025, 15:15

Type Values Removed Values Added
CWE CWE-787

21 Nov 2024, 07:25

Type Values Removed Values Added
Summary
  • (es) El análisis de un archivo X_B y PRT creado con fines malintencionados puede obligar a Autodesk Maya 2023 y 2022 a leer más allá del búfer asignado. Esta vulnerabilidad, junto con otras vulnerabilidades, podría provocar la ejecución de código en el contexto del proceso actual.
References () https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0020 - Vendor Advisory () https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0020 - Vendor Advisory

Information

Published : 2022-12-19 16:15

Updated : 2025-04-17 15:15


NVD link : CVE-2022-42946

Mitre link : CVE-2022-42946

CVE.ORG link : CVE-2022-42946


JSON object : View

Products Affected

autodesk

  • maya
CWE
CWE-125

Out-of-bounds Read

CWE-787

Out-of-bounds Write