Unrated severityNVD Advisory· Published Nov 24, 2009· Updated Apr 23, 2026
CVE-2009-3577
CVE-2009-3577
Description
Autodesk 3D Studio Max (3DSMax) 6 through 9 and 2008 through 2010 allows remote attackers to execute arbitrary code via a .max file with a MAXScript statement that calls the DOSCommand method, related to "application callbacks."
Affected products
7cpe:2.3:a:autodesk:3ds_max:2008:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:autodesk:3ds_max:2008:*:*:*:*:*:*:*
- cpe:2.3:a:autodesk:3ds_max:2009:*:*:*:*:*:*:*
- cpe:2.3:a:autodesk:3ds_max:2010:*:*:*:*:*:*:*
- cpe:2.3:a:autodesk:3ds_max:6:*:*:*:*:*:*:*
- cpe:2.3:a:autodesk:3ds_max:7:*:*:*:*:*:*:*
- cpe:2.3:a:autodesk:3ds_max:8:*:*:*:*:*:*:*
- cpe:2.3:a:autodesk:3ds_max:9:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4News mentions
0No linked articles in our index yet.