Junglewise Threat Intelligence

CVE-2026-7452: Autodesk 3ds Max memory corruption in WRL parsing

CVE-2026-7452 · Severity: high · CVSS 7.8 · Published 2026-05-26

Technologies: Autodesk 3ds Max. Vendors: Autodesk.

Executive brief

Autodesk 3ds Max, a professional 3D modeling and rendering software, is vulnerable to a memory corruption issue when processing specific file types. An attacker could trick a user into opening a specially crafted WRL file, allowing the attacker to take control of the user's computer or run unauthorized commands. This could lead to the theft of sensitive design data or a complete compromise of the workstation.

Technical details

A memory corruption vulnerability exists in Autodesk 3ds Max due to improper handling of WRL (VRML) files. The root cause is identified as a buffer overflow (CWE-120) during the parsing process. An attacker can exploit this by providing a specially crafted WRL file to a user; when the application attempts to parse the file, it triggers a memory corruption event. This is a local attack vector that requires user interaction (opening the file). Successful exploitation allows for arbitrary code execution in the context of the current process, potentially leading to full system compromise.

Affected products

  • Autodesk 3ds Max

Timeline

  • 2026-05-26: disclosed
  • 2026-05-26: advisory

References

Related threats