CVE-2025-6633
published 2025-08-06CVE-2025-6633: A maliciously crafted RBG file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this…
PriorityP341high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.20%
9.9th percentile
A maliciously crafted RBG file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| autodesk | 3ds_max | >= 2026 < 2026.2 | 2026.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Umbraco CMS has an arbitrary file upload vulnerability
ghsa·2025-12-22
CVE-2025-67288 [MEDIUM] CWE-434 Umbraco CMS has an arbitrary file upload vulnerability
Umbraco CMS has an arbitrary file upload vulnerability
An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code via uploading a crafted PDF file. While Umbraco provides [hooks to perform file validation](https://docs.umbraco.com/umbraco-cms/reference/security/serverside-file-validation), it does not do implement filtering by default. Users are expected to implement their own validation.
Note: This vulnerability is [disputed by Ubraco](https://github.com/github/advisory-database/pull/6633).
GHSA
GHSA-p746-77p9-8wj5: A maliciously crafted RBG file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability
ghsa_unreviewed·2025-08-06
CVE-2025-6633 [HIGH] CWE-787 GHSA-p746-77p9-8wj5: A maliciously crafted RBG file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability
A maliciously crafted RBG file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-08-06
Published