This application requires Javascript for optimal performance.

DAZ.Studio.Arbitrary.Script.Execution

Release Date

Dec 22, 2009

Severity

high

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates an attack attempt against a command-execution vulnerability in DAZ Studio.

The vulnerability is caused by an error when the vulnerable software handles a malicious .ds script. It allows a remote attacker to execute arbitrary code via sending a crafted .ds script.

Affected Products

DAZ Studio 2.3.3.161
DAZ Studio 2.3.3.163
DAZ Studio 3.0.1.135
Other older versions are possibily affected too

Recommended Actions

Currently we are not aware of any officially supplied patch for this issue.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2009-4148

Reference/s

http://www.securityfocus.com/bid/37176 (BugTraq)

Reference: VID-18011