CVE-2022-0545
CVE-2022-0545
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 1.1%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Lifecycle
24 Feb 2022Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
An integer overflow in the processing of loaded 2D images leads to a write-what-where vulnerability and an out-of-bounds read vulnerability, allowing an attacker to leak sensitive information or achieve code execution in the context of the Blender process when a specially crafted image file is loaded. This flaw affects Blender versions prior to 2.83.19, 2.93.8 and 3.1.
Affected products
n/a · BlenderWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →