Executive brief
Autodesk 3ds Max is a professional 3D modeling and animation software widely used in film, game development, and design studios. A crafted ABC file can trigger an out-of-bounds memory write when parsed by the application, allowing an attacker to crash the program, corrupt data, or execute arbitrary code if the user opens a malicious file.
Technical details
This vulnerability is an out-of-bounds write in the ABC (Alembic) file parser of Autodesk 3ds Max. The vulnerability exists in the file parsing logic when processing a maliciously crafted ABC file. An attacker can exploit this by distributing a malicious ABC file that, when opened in 3ds Max, triggers an out-of-bounds write condition. No authentication or special privileges are required—only user interaction (opening the file) is needed. Successful exploitation can lead to arbitrary code execution in the context of the 3ds Max process, data corruption, or denial of service through application crash. A patch is expected to be available from Autodesk.
Affected products
- Autodesk 3ds Max
Timeline
- 2026-08-24: disclosed