Executive brief
Autodesk 3ds Max, a professional 3D modeling and rendering software, is vulnerable to a memory corruption issue when processing specially crafted WRL files. If a user is tricked into opening a malicious file, an attacker could gain the ability to run unauthorized code on the user's computer. This could lead to the theft of sensitive design data, full system compromise, or disruption of creative operations.
Technical details
A memory corruption vulnerability exists in Autodesk 3ds Max due to improper handling of WRL (VRML) files. The flaw is categorized as a 'Classic Buffer Overflow' (CWE-120), occurring when the application parses a maliciously crafted input file without sufficient size validation. An attacker can exploit this by convincing a user to open a specially crafted WRL file, leading to arbitrary code execution in the context of the current process. The attack vector is local and requires user interaction, but does not require elevated privileges. Users are advised to refer to Autodesk security advisory ADSK-SA-2026-0006 for patching information.
Affected products
- Autodesk 3ds Max
Timeline
- 2026-05-26: advisory: Initial advisory published by Autodesk and NVD.