CVE-2025-4605

Severity
6.6MEDIUM
EPSS
0.2%
top 63.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 11

Description

A maliciously crafted .usdc file, when loaded through Autodesk Maya, can force an uncontrolled memory allocation vulnerability. A malicious actor may leverage this vulnerability to cause a denial-of-service (DoS), or cause data corruption.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:HExploitability: 1.8 | Impact: 4.7

Affected Packages5 packages

CVEListV5autodesk/maya20252025.3.1
NVDautodesk/maya20252025.3.1
CVEListV5autodesk/usd_for_mayaMaya USD 0.31.0Maya USD 0.32.0
CVEListV5autodesk/usd_for_3ds_maxMax USD 0.10Max USD 0.11

🔴Vulnerability Details

2
GHSA
GHSA-x8wm-pq66-9pp3: A maliciously crafted2025-06-11
CVEList
USD File Parsing Memory Allocation Vulnerability2025-06-11
CVE-2025-4605 (MEDIUM CVSS 6.6) | A maliciously crafted .usdc file | cvebase.io