Junglewise Threat Intelligence

CVE-2026-0538: Autodesk 3ds Max out-of-bounds write in GIF parsing

CVE-2026-0538 · Severity: high · CVSS 8.4 · Published 2026-02-04

Technologies: Autodesk 3ds Max. Vendors: Autodesk.

Executive brief

Autodesk 3ds Max, a professional 3D modeling and rendering software, is vulnerable to a security flaw when processing specially crafted GIF images. An attacker could use a malicious image file to gain control over the software and execute unauthorized commands on the user's computer. This could lead to the theft of sensitive design data, system compromise, or the installation of further malware.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in Autodesk 3ds Max during the parsing of GIF image files. The flaw is triggered when the application processes a maliciously crafted GIF, allowing an attacker to write data past the end of an allocated buffer. This memory corruption can be leveraged to achieve arbitrary code execution in the context of the current process. The attack is local in nature, requiring the victim to open or process a malicious file. Autodesk has addressed this in version 2026.3.2.

Affected products

  • Autodesk 3ds Max 2026 before 2026.3.2

Timeline

  • 2026-02-04: disclosed
  • 2026-02-04: advisory

References

Related threats