Description
Autodesk 3D Studio Max (3DSMax) 6 through 9 and 2008 through 2010 allows remote attackers to execute arbitrary code via a .max file with a MAXScript statement that calls the DOSCommand method, related to "application callbacks."
Affected products
- autodesk / 3ds_max6 – 6
- autodesk / 3ds_max7 – 7
- autodesk / 3ds_max8 – 8
- autodesk / 3ds_max9 – 9
- autodesk / 3ds_max2008 – 2008
- autodesk / 3ds_max2009 – 2009
- autodesk / 3ds_max2010 – 2010