Autodesk 3ds Max Out-of-Bounds Write Vulnerability Allowing Arbitrary Code Execution

Vulnerability

An out-of-bounds write vulnerability has been identified in Autodesk 3ds Max 2026. When a maliciously crafted JPG file is parsed by the application, it can lead to memory corruption. This vulnerability can be exploited to execute arbitrary code within the context of the current process.

Impact

Exploitation of this vulnerability allows for arbitrary code execution in the context of the current process.

Remediation

Users are advised to update to Autodesk 3ds Max 2026.3. The update can be obtained through Autodesk Access or the Accounts Portal.

Added: Nov 12, 2025, 6:36 PM
Updated: Nov 12, 2025, 6:36 PM

Vulnerability Rating

Custom Algorithm
spread
4.2
impact
10.0
exploitability
4.4
remediation
7.7
relevance
1.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.