Autodesk 3ds Max Stack Exhaustion Vulnerability Leading to Denial-of-Service

Vulnerability

A stack exhaustion vulnerability has been identified in Autodesk 3ds Max versions 2026 and 2027, prior to 2026.1 and 2027.1. This vulnerability allows a denial-of-service condition when a maliciously crafted WRL file is parsed by the application.

Impact

Exploitation of this vulnerability leads to a denial-of-service condition, causing the application to become unresponsive or unavailable.

Remediation

Users are advised to update to Autodesk 3ds Max versions 2026.1 or 2027.1 via the Autodesk Access application or the Accounts Portal.

Added: May 26, 2026, 10:29 PM
Updated: May 26, 2026, 10:29 PM

Vulnerability Rating

Custom Algorithm
spread
4.2
impact
0.6
exploitability
4.2
remediation
7.9
relevance
9.6
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.