Omniverse Kit contains a vulnerability in the reference applications Create, Audio2Face, Isaac Sim, View, Code, and Machinima. These applications allow executable Python code to be embedded in Universal Scene Description (USD) files to customize all aspects of a scene. If a user opens a USD file that contains embedded Python code in one of these applications, the embedded Python code automatically runs with the privileges of the user who opened the file. As a result, an unprivileged remote attacker could craft a USD file containing malicious Python code and persuade a local user to open the file, which may lead to information disclosure, data tampering, and denial of service.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://nvidia.custhelp.com/app/answers/detail/a_id/5418 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: nvidia
Published: 2023-01-12T19:38:55.196Z
Updated: 2024-08-03T13:03:45.907Z
Reserved: 2022-10-03T14:20:26.202Z
Link: CVE-2022-42268
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-01-13T06:15:11.843
Modified: 2024-11-21T07:24:37.537
Link: CVE-2022-42268
Redhat
No data.