Junglewise Threat Intelligence

CVE-2026-7450: Autodesk 3ds Max NULL Pointer Dereference in PAR file parsing

CVE-2026-7450 · Severity: medium · CVSS 5.3 · Published 2026-05-26

Technologies: Autodesk 3ds Max. Vendors: Autodesk.

Executive brief

Autodesk 3ds Max, a professional 3D modeling and rendering software, is vulnerable to a crash when processing specifically designed PAR files. An attacker could trick a user into opening a malicious file, causing the application to shut down unexpectedly. This results in a denial-of-service, potentially leading to loss of unsaved work and disruption of production workflows.

Technical details

A NULL Pointer Dereference (CWE-476) exists within Autodesk 3ds Max's handling of PAR files. The vulnerability is triggered during the parsing process when the application attempts to read or write to a memory location that is expected to be valid but is instead NULL. This is a local attack vector requiring user interaction, specifically that a user opens a maliciously crafted file. Successful exploitation results in an application crash (denial-of-service). The CVSS score of 5.3 reflects limited impact on confidentiality, integrity, and availability in a local context.

Affected products

  • Autodesk 3ds Max

Timeline

  • 2026-05-26: disclosed: Initial disclosure by Autodesk via NVD
  • 2026-05-26: advisory

References

Related threats