Junglewise Threat Intelligence

CVE-2026-7455: Autodesk 3ds Max out-of-bounds write in FLT file parsing

CVE-2026-7455 · Severity: high · CVSS 7.8 · Published 2026-08-24

Technologies: Autodesk 3ds Max. Vendors: Autodesk.

Executive brief

Autodesk 3ds Max is a 3D modeling and animation software widely used in design and entertainment workflows. A malicious FLT (OpenFlight) file can trigger an out-of-bounds memory write when opened in 3ds Max, potentially allowing an attacker to crash the application, corrupt data, or execute arbitrary code on a user's workstation.

Technical details

This is an out-of-bounds write vulnerability in Autodesk 3ds Max's FLT (OpenFlight) file parser. The vulnerability is triggered when a maliciously crafted FLT file is parsed by the application, allowing an attacker to write data beyond the intended buffer boundaries. The attack vector is local, requiring user interaction (opening a malicious file). Successful exploitation can result in application crash, data corruption, or arbitrary code execution with the privileges of the user running 3ds Max. No patch information is currently available from the references provided.

Affected products

  • Autodesk 3ds Max <UNKNOWN>

Timeline

  • 2026-08-24: disclosed

References

Related threats