Autodesk 3ds Max Out-of-Bounds Read Vulnerability Allowing Code Execution

Vulnerability

An out-of-bounds read vulnerability has been identified in Autodesk 3ds Max 2026. When a maliciously crafted PSD file is linked or imported into the application, it can trigger this vulnerability. Affected users may experience application crashes, unauthorized access to sensitive data, or execution of arbitrary code within the current process context.

Impact

Exploitation of this vulnerability can lead to application crashes, unauthorized reading of sensitive data, or execution of arbitrary code in the context of the current process.

Remediation

Users are advised to update to Autodesk 3ds Max 2026.2, available through Autodesk Access or the Accounts Portal.

Added: Aug 6, 2025, 9:24 PM
Updated: Aug 6, 2025, 9:24 PM

Vulnerability Rating

Custom Algorithm
spread
4.2
impact
10.0
exploitability
4.4
remediation
7.7
relevance
0.3
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.