Impact
A maliciously crafted SVG file can trigger an uncontrolled recursion in Autodesk 3ds Max when parsed, causing the application to terminate unexpectedly. The severity is limited to denial of service against the running application, as the vulnerability does not grant command execution or data disclosure. The weakness lies in resource exhaustion due to recursion as identified by CWE‑674.
Affected Systems
Autodesk 3ds Max versions from 2026 through 2027 are affected. Any installation of the product that includes the SVG file parser without the latest patch is susceptible.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate risk. The EPSS score is not available, and the vulnerability is not listed in CISA KEV. The likely attack vector is local file processing; an attacker can supply a crafted SVG file to a user who opens it in the application, leading to a denial of service. No remote exploitation path is documented, so mitigation focuses on preventing the user from opening untrusted files until patched.
OpenCVE Enrichment