Junglewise Threat Intelligence

CVE-2026-0537: Autodesk 3ds Max memory corruption in RGB file parsing

CVE-2026-0537 · Severity: high · CVSS 8.4 · Published 2026-02-04

Technologies: Autodesk 3ds Max. Vendors: Autodesk.

Executive brief

Autodesk 3ds Max, a professional 3D modeling and rendering software, is vulnerable to a memory corruption issue when processing specifically designed RGB image files. An attacker could use this flaw to take control of a user's system or execute unauthorized commands if the user opens a malicious file. This could lead to the theft of sensitive design data or a complete compromise of the workstation.

Technical details

A memory corruption vulnerability exists in Autodesk 3ds Max due to an out-of-bounds write (CWE-787) during the parsing of RGB files. By providing a specially crafted RGB file, an attacker can trigger this vulnerability to execute arbitrary code in the context of the current process. The attack vector is local, typically requiring a user to open the malicious file. Autodesk has addressed this in version 2026.3.2.

Affected products

  • Autodesk 3ds Max 2026 before 2026.3.2

Timeline

  • 2026-02-04: disclosed
  • 2026-02-04: advisory
  • 2026-02-06: patched: NIST analysis indicates fix in 2026.3.2

References

Related threats