Executive brief
Autodesk 3ds Max, a professional 3D modeling and rendering software, is vulnerable to a crash when processing specifically designed PAR files. An attacker could trick a user into opening a malicious file, causing the application to shut down unexpectedly. This results in a denial-of-service, potentially leading to loss of unsaved work and disruption of production workflows.
Technical details
A NULL Pointer Dereference (CWE-476) exists within Autodesk 3ds Max's handling of PAR files. The vulnerability is triggered during the parsing process when the application attempts to read or write to a memory location that is expected to be valid but is instead NULL. This is a local attack vector requiring user interaction, specifically that a user opens a maliciously crafted file. Successful exploitation results in an application crash (denial-of-service). The CVSS score of 5.3 reflects limited impact on confidentiality, integrity, and availability in a local context.
Affected products
- Autodesk 3ds Max
Timeline
- 2026-05-26: disclosed: Initial disclosure by Autodesk via NVD
- 2026-05-26: advisory