Executive brief
Autodesk 3ds Max is a 3D modeling and animation software widely used in visual effects, game development, and product design. A vulnerability in its SVG file parser can be exploited by opening a maliciously crafted SVG file, allowing an attacker to execute arbitrary code on the user's machine with full privileges of the 3ds Max process.
Technical details
The vulnerability is a memory corruption flaw in Autodesk 3ds Max's SVG parsing functionality. When the application processes a specially crafted SVG file, it triggers a memory corruption condition that can be leveraged for arbitrary code execution. The attack requires user interaction (opening a malicious SVG file) and is local in nature. No authentication is required beyond the ability to provide a file to the victim. An attacker can achieve full code execution in the context of the application process. The vulnerability was published on 2026-08-24; patch availability is not confirmed from the available advisory references.
Affected products
- Autodesk 3ds Max
Timeline
- 2026-08-24: disclosed