Junglewise Threat Intelligence

CVE-2026-7451: Autodesk 3ds Max out-of-bounds write in TIF parsing

CVE-2026-7451 · Severity: high · CVSS 7.8 · Published 2026-05-26

Technologies: Autodesk 3ds Max. Vendors: Autodesk.

Executive brief

Autodesk 3ds Max, a professional 3D modeling and rendering software, is vulnerable to a security flaw when processing certain image files. An attacker could trick a user into opening a specially crafted TIF file, which could lead to a system crash, data corruption, or the unauthorized execution of commands on the user's computer. This could compromise sensitive design data or allow an attacker to gain a foothold in a creative professional's workstation.

Technical details

An Out-of-Bounds Write vulnerability (CWE-787) exists in Autodesk 3ds Max during the parsing of TIF image files. The flaw is triggered when the application processes a maliciously crafted TIF file, leading to memory corruption. This is a local attack vector that requires user interaction, specifically the opening of the malicious file. Successful exploitation allows an attacker to execute arbitrary code with the privileges of the 3ds Max process, potentially leading to full system compromise or persistent access. The vulnerability was disclosed by Autodesk with a CVSS score of 7.8.

Affected products

  • Autodesk 3ds Max

Timeline

  • 2026-05-26: disclosed: Initial disclosure by Autodesk and NVD publication.
  • 2026-05-26: advisory

References

Related threats