Executive brief
Autodesk 3ds Max, a professional 3D modeling and rendering software, is vulnerable to a memory corruption issue when processing specifically designed RGB image files. An attacker could use this flaw to take control of a user's system or execute unauthorized commands if the user opens a malicious file. This could lead to the theft of sensitive design data or a complete compromise of the workstation.
Technical details
A memory corruption vulnerability exists in Autodesk 3ds Max due to an out-of-bounds write (CWE-787) during the parsing of RGB files. By providing a specially crafted RGB file, an attacker can trigger this vulnerability to execute arbitrary code in the context of the current process. The attack vector is local, typically requiring a user to open the malicious file. Autodesk has addressed this in version 2026.3.2.
Affected products
- Autodesk 3ds Max 2026 before 2026.3.2
Timeline
- 2026-02-04: disclosed
- 2026-02-04: advisory
- 2026-02-06: patched: NIST analysis indicates fix in 2026.3.2