Executive brief
Autodesk 3ds Max is a professional 3D modeling and animation tool used across design and entertainment industries. A specially crafted SVG file can cause the application to crash due to an uncontrolled recursion flaw, allowing an attacker to disrupt a user's work and availability when a malicious file is opened.
Technical details
The vulnerability is an uncontrolled recursion flaw in Autodesk 3ds Max's SVG file parser. When a maliciously crafted SVG file is parsed by the application, the recursive parsing logic fails to properly limit recursion depth, causing a stack overflow. An attacker can deliver a malicious SVG file to a user (via email, file sharing, or web download), and if opened in 3ds Max, triggers the crash. The vulnerability requires user interaction (opening the file). Patches or fixes should be available from Autodesk's security advisory.
Affected products
- Autodesk 3ds Max
Timeline
- 2026-08-24: disclosed