Junglewise Threat Intelligence

CVE-2026-0660: Autodesk 3ds Max stack buffer overflow in GIF parsing

CVE-2026-0660 · Severity: high · CVSS 8.4 · Published 2026-02-04

Technologies: Autodesk 3ds Max. Vendors: Autodesk.

Executive brief

Autodesk 3ds Max, a professional 3D modeling and rendering software, is vulnerable to a security flaw when processing specially crafted GIF images. If a user opens a malicious GIF file using the software, an attacker could potentially take control of the application or the underlying computer system. This could lead to the theft of sensitive design data, unauthorized access to corporate files, or a complete disruption of creative operations.

Technical details

A stack-based buffer overflow (CWE-121) exists in Autodesk 3ds Max during the parsing of GIF image files. The vulnerability is triggered when the application processes a maliciously crafted GIF file, leading to memory corruption. An attacker can exploit this by providing a specially designed file to a user, which, when opened, allows for arbitrary code execution within the context of the 3ds Max process. The issue affects versions of 3ds Max 2026 prior to version 2026.3.2. While the initial assessment suggested user interaction was required, updated metrics indicate a local attack vector with no specific user interaction or privileges required beyond the ability to have the application parse the file.

Affected products

  • Autodesk 3ds Max 2026 up to (excluding) 2026.3.2

Timeline

  • 2026-02-04: disclosed
  • 2026-02-04: advisory
  • 2026-02-06: patched: Fix identified in version 2026.3.2

References

Related threats