Executive brief
Autodesk 3ds Max, a professional 3D modeling and rendering software, is vulnerable to a security flaw when processing certain image files. An attacker could trick a user into opening a specially crafted TIF file, which could lead to a system crash, data corruption, or the unauthorized execution of commands on the user's computer. This could compromise sensitive design data or allow an attacker to gain a foothold in a creative professional's workstation.
Technical details
An Out-of-Bounds Write vulnerability (CWE-787) exists in Autodesk 3ds Max during the parsing of TIF image files. The flaw is triggered when the application processes a maliciously crafted TIF file, leading to memory corruption. This is a local attack vector that requires user interaction, specifically the opening of the malicious file. Successful exploitation allows an attacker to execute arbitrary code with the privileges of the 3ds Max process, potentially leading to full system compromise or persistent access. The vulnerability was disclosed by Autodesk with a CVSS score of 7.8.
Affected products
- Autodesk 3ds Max
Timeline
- 2026-05-26: disclosed: Initial disclosure by Autodesk and NVD publication.
- 2026-05-26: advisory