Executive brief
Autodesk 3ds Max, a professional 3D modeling and rendering software, is vulnerable to a memory corruption issue when processing specially crafted RGB image files. An attacker who convinces a user to open a malicious file could gain full control over the user's system or execute unauthorized commands. This could lead to the theft of intellectual property, data loss, or a complete compromise of the workstation.
Technical details
A memory corruption vulnerability exists in Autodesk 3ds Max due to an out-of-bounds write (CWE-787) during the parsing of RGB files. By providing a specially crafted RGB file, an attacker can trigger this vulnerability to corrupt memory and execute arbitrary code in the context of the current process. The attack vector is local, meaning a user must be tricked into opening the malicious file. The vulnerability affects versions of 3ds Max 2026 prior to version 2026.3.2, where a fix has been implemented.
Affected products
- Autodesk 3ds Max 2026 before 2026.3.2
Timeline
- 2026-02-04: disclosed
- 2026-02-04: advisory