Executive brief
Autodesk 3ds Max is a 3D modeling and animation software widely used in design and entertainment workflows. A malicious FLT (OpenFlight) file can trigger an out-of-bounds memory write when opened in 3ds Max, potentially allowing an attacker to crash the application, corrupt data, or execute arbitrary code on a user's workstation.
Technical details
This is an out-of-bounds write vulnerability in Autodesk 3ds Max's FLT (OpenFlight) file parser. The vulnerability is triggered when a maliciously crafted FLT file is parsed by the application, allowing an attacker to write data beyond the intended buffer boundaries. The attack vector is local, requiring user interaction (opening a malicious file). Successful exploitation can result in application crash, data corruption, or arbitrary code execution with the privileges of the user running 3ds Max. No patch information is currently available from the references provided.
Affected products
- Autodesk 3ds Max <UNKNOWN>
Timeline
- 2026-08-24: disclosed