cbcvebase.
CVE-2025-4605
published 2025-06-11

CVE-2025-4605: A maliciously crafted .usdc file, when loaded through Autodesk Maya, can force an uncontrolled memory allocation vulnerability. A malicious actor may leverage…

PriorityP424medium6.6CVSS 3.1
AVLACLPRNUIRSUCLILAH
EPSS
0.18%
7.5th percentile
A maliciously crafted .usdc file, when loaded through Autodesk Maya, can force an uncontrolled memory allocation vulnerability. A malicious actor may leverage this vulnerability to cause a denial-of-service (DoS), or cause data corruption.

Affected

5 ranges
VendorProductVersion rangeFixed in
autodeskmaya>= 2025 < 2025.3.12025.3.1
autodeskuniversal_scene_description
autodeskuniversal_scene_description
autodeskusd_for_3ds_max>= Max USD 0.10 < Max USD 0.11Max USD 0.11
autodeskusd_for_maya>= Maya USD 0.31.0 < Maya USD 0.32.0Maya USD 0.32.0
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.