Executive brief
Autodesk 3ds Max, a professional 3D modeling and rendering software, is vulnerable to a denial-of-service attack when processing specifically designed VRML (.wrl) files. An attacker could trick a user into opening a malicious file, causing the application to crash and potentially resulting in the loss of unsaved work or disruption of production workflows.
Technical details
A stack exhaustion vulnerability exists in Autodesk 3ds Max due to uncontrolled recursion (CWE-674) during the parsing of VRML (.wrl) files. The flaw is triggered when the application processes a specially crafted file that exceeds the stack memory limits, leading to an application crash. This is a local attack vector that requires user interaction, specifically the opening of a malicious file. Successful exploitation results in a denial-of-service (DoS) condition.
Affected products
- Autodesk 3ds Max
Timeline
- 2026-05-26: disclosed
- 2026-05-26: advisory