Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2009-3850Code Injection in Blender

CWE-94Code Injection7 documents6 sources
Severity
9.3CRITICALNVD
EPSS
4.2%
top 11.26%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedNov 6
Latest updateMay 2

Description

Blender 2.34, 2.35a, 2.40, and 2.49b allows remote attackers to execute arbitrary code via a .blend file that contains Python statements in the onLoad action of a ScriptLink SDNA.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages2 packages

NVDblender/blender4 versions+3

🔴Vulnerability Details

2
GHSA
GHSA-cfxm-x8mw-xvmf: Blender 22022-05-02
OSV
CVE-2009-3850: Blender 22009-11-06

💥Exploits & PoCs

1
Exploit-DB
Blender 2.34/2.35a/2.4/2.49b - '.blend' Command Injection2009-11-05

📋Vendor Advisories

1
Debian
CVE-2009-3850: blender - Blender 2.34, 2.35a, 2.40, and 2.49b allows remote attackers to execute arbitrar...2009

💬Community

2
Bugzilla
CVE-2009-3850 Blender: Arbitrary code execution via malicious .blend file [epel-all]2012-08-25
Bugzilla
CVE-2009-3850 Blender: Arbitrary code execution via malicious .blend file2009-11-06
CVE-2009-3850 — Code Injection in Blender | cvebase