Autodesk Arnold and 3ds Max Out-of-Bounds Write Vulnerability Allowing Arbitrary Code Execution

Vulnerability

A vulnerability allowing out-of-bounds write has been identified in the USD functionality of Autodesk Arnold and Autodesk 3ds Max. When a maliciously crafted USD file is loaded or imported into these applications, it can lead to arbitrary code execution within the context of the current process. This vulnerability affects several versions of Autodesk USD for Arnold, Autodesk Arnold, and Autodesk 3ds Max 2026.2.

Impact

Exploitation of this vulnerability can lead to arbitrary code execution in the context of the current process.

Remediation

Users are advised to update to Autodesk USD for Arnold 7.4.4.2, Autodesk Arnold 7.4.4.2, or Autodesk 3ds Max 2026.3.2. These updates are available through the Autodesk Access application, the Accounts Portal, or the Arnold USD GitHub repository.

Added: Feb 4, 2026, 6:40 PM
Updated: Feb 4, 2026, 6:40 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
4.3
remediation
0.0
relevance
2.7
threat
3.2
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.