Autodesk 3Ds Max vulnerabilities
25 known vulnerabilities affecting autodesk/3ds_max.
Total CVEs
25
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH21MEDIUM3
Vulnerabilities
Page 1 of 2
CVE-2009-3577P3CRITICALCVSS 9.3PoCv6v7+5 more2009-11-24
CVE-2009-3577 [CRITICAL] CWE-94 CVE-2009-3577: Autodesk 3D Studio Max (3DSMax) 6 through 9 and 2008 through 2010 allows remote attackers to execute
Autodesk 3D Studio Max (3DSMax) 6 through 9 and 2008 through 2010 allows remote attackers to execute arbitrary code via a .max file with a MAXScript statement that calls the DOSCommand method, related to "application callbacks."
nvd
CVE-2026-0660P3HIGHCVSS 8.4≥ 2026, < 2026.3.22026-02-04
CVE-2026-0660 [HIGH] CWE-121 CVE-2026-0660: A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can cause a Stack-Based Buffer
A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can cause a Stack-Based Buffer Overflow vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
nvd
CVE-2026-0661P3HIGHCVSS 8.4≥ 2026, < 2026.3.22026-02-04
CVE-2026-0661 [HIGH] CWE-787 CVE-2026-0661: A maliciously crafted RGB file, when parsed through Autodesk 3ds Max, can force a Memory Corruption
A maliciously crafted RGB file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
nvd
CVE-2026-0537P3HIGHCVSS 8.4≥ 2026, < 2026.3.22026-02-04
CVE-2026-0537 [HIGH] CWE-787 CVE-2026-0537: A maliciously crafted RGB file, when parsed through Autodesk 3ds Max, can force a Memory Corruption
A maliciously crafted RGB file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
nvd
CVE-2026-0538P3HIGHCVSS 8.4≥ 2026, < 2026.3.22026-02-04
CVE-2026-0538 [HIGH] CWE-787 CVE-2026-0538: A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Wri
A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
nvd
CVE-2026-0536P3HIGHCVSS 7.8≥ 2026, < 2026.3.22026-02-04
CVE-2026-0536 [HIGH] CWE-787 CVE-2026-0536: A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can cause a Stack-Based Buffer
A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can cause a Stack-Based Buffer Overflow vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
nvd
CVE-2026-7451P3HIGHCVSS 7.8v2026v2027+2 more2026-05-26
CVE-2026-7451 [HIGH] CWE-787 CVE-2026-7451: A maliciously crafted TIF file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Wri
A maliciously crafted TIF file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
nvd
CVE-2026-0659P3HIGHCVSS 7.8≥ 2026.2, < 2026.3.22026-02-04
CVE-2026-0659 [HIGH] CWE-787 CVE-2026-0659: A maliciously crafted USD file, when loaded or imported into Autodesk Arnold or Autodesk 3ds Max, ca
A maliciously crafted USD file, when loaded or imported into Autodesk Arnold or Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
nvd
CVE-2026-7452P3HIGHCVSS 7.8v2026v2027+2 more2026-05-26
CVE-2026-7452 [HIGH] CWE-120 CVE-2026-7452: A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption
A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
nvd
CVE-2026-7454P3HIGHCVSS 7.8v2026v2027+2 more2026-05-26
CVE-2026-7454 [HIGH] CWE-120 CVE-2026-7454: A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption
A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
nvd
CVE-2025-6634P3HIGHCVSS 7.8≥ 2026, < 2026.22025-08-06
CVE-2025-6634 [HIGH] CWE-120 CVE-2025-6634: A maliciously crafted TGA file, when linked or imported into Autodesk 3ds Max, can force a Memory Co
A maliciously crafted TGA file, when linked or imported into Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
nvd
CVE-2025-6633P3HIGHCVSS 7.8≥ 2026, < 2026.22025-08-06
CVE-2025-6633 [HIGH] CWE-787 CVE-2025-6633: A maliciously crafted RBG file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Wri
A maliciously crafted RBG file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
nvd
CVE-2025-11795P3HIGHCVSS 7.8≥ 2026, < 2026.32025-11-12
CVE-2025-11795 [HIGH] CWE-787 CVE-2025-11795: A maliciously crafted JPG file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Wri
A maliciously crafted JPG file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
nvd
CVE-2025-11797P3HIGHCVSS 7.8≥ 2026, < 2026.32025-11-12
CVE-2025-11797 [HIGH] CWE-416 CVE-2025-11797: A maliciously crafted DWG file, when parsed through Autodesk 3ds Max, can force a Use-After-Free vul
A maliciously crafted DWG file, when parsed through Autodesk 3ds Max, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
nvd
CVE-2026-0662P3HIGHCVSS 7.8≥ 2026, < 2026.3.22026-02-04
CVE-2026-0662 [HIGH] CWE-426 CVE-2026-0662: A maliciously crafted project directory, when opening a max file in Autodesk 3ds Max, could lead to
A maliciously crafted project directory, when opening a max file in Autodesk 3ds Max, could lead to execution of arbitrary code in the context of the current process due to an Untrusted Search Path being utilized.
nvd
CVE-2022-27871P3HIGHCVSS 7.8v2021v20222022-06-21
CVE-2022-27871 [HIGH] CWE-770 CVE-2022-27871: Autodesk AutoCAD product suite, Revit, Design Review and Navisworks releases using PDFTron prior to
Autodesk AutoCAD product suite, Revit, Design Review and Navisworks releases using PDFTron prior to 9.1.17 version may be used to write beyond the allocated buffer while parsing PDF files. This vulnerability may be exploited to execute arbitrary code.
nvd
CVE-2022-25793P3HIGHCVSS 7.8≥ 2020, < 2020.3.6≥ 2021, < 2021.3.10+1 more2022-08-10
CVE-2022-25793 [HIGH] CWE-1284 CVE-2022-25793: A Stack-based Buffer Overflow Vulnerability in Autodesk 3ds Max 2022, 2021, and 2020 may lead to cod
A Stack-based Buffer Overflow Vulnerability in Autodesk 3ds Max 2022, 2021, and 2020 may lead to code execution through the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer when parsing ActionScript Byte Code files. This vulnerability may allow arbitrary code execution on affected
nvd
CVE-2025-6632P3HIGHCVSS 7.8≥ 2026, < 2026.22025-08-06
CVE-2025-6632 [HIGH] CWE-125 CVE-2025-6632: A maliciously crafted PSD file, when linked or imported into Autodesk 3ds Max, can force an Out-of-B
A maliciously crafted PSD file, when linked or imported into Autodesk 3ds Max, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
nvd
CVE-2025-5039P3HIGHCVSS 7.8≥ 2027, < 2027.1≥ 2026, < 2026.3.32025-07-24
CVE-2025-5039 [HIGH] CWE-426 CVE-2025-5039: A maliciously crafted binary file, when present while loading files in certain Autodesk applications
A maliciously crafted binary file, when present while loading files in certain Autodesk applications, could lead to execution of arbitrary code in the context of the current process due to an untrusted search path being utilized.
nvd
CVE-2022-27532P3HIGHCVSS 7.8≥ 2021, < 2021.3.8≥ 2022, < 2022.3.32022-06-16
CVE-2022-27532 [HIGH] CWE-787 CVE-2022-27532: A maliciously crafted TIF file in Autodesk 3ds Max 2022 and 2021 can be used to write beyond the all
A maliciously crafted TIF file in Autodesk 3ds Max 2022 and 2021 can be used to write beyond the allocated buffer while parsing TIF files. This vulnerability in conjunction with other vulnerabilities could lead to arbitrary code execution.
nvd
1 / 2Next →