CVE-2025-4605
published 2025-06-11CVE-2025-4605: A maliciously crafted .usdc file, when loaded through Autodesk Maya, can force an uncontrolled memory allocation vulnerability. A malicious actor may leverage…
PriorityP424medium6.6CVSS 3.1
AVLACLPRNUIRSUCLILAH
EPSS
0.18%
7.5th percentile
A maliciously crafted .usdc file, when loaded through Autodesk Maya, can force an uncontrolled memory allocation vulnerability. A malicious actor may leverage this vulnerability to cause a denial-of-service (DoS), or cause data corruption.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| autodesk | maya | >= 2025 < 2025.3.1 | 2025.3.1 |
| autodesk | universal_scene_description | — | — |
| autodesk | universal_scene_description | — | — |
| autodesk | usd_for_3ds_max | >= Max USD 0.10 < Max USD 0.11 | Max USD 0.11 |
| autodesk | usd_for_maya | >= Maya USD 0.31.0 < Maya USD 0.32.0 | Maya USD 0.32.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-06-11
Published