Description
A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
Published: 2026-08-24
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Memory corruption that may allow code execution
Action: Patch
AI Analysis

Impact

A maliciously crafted SVG file, when processed by Autodesk 3ds Max, triggers an out‑of‑bounds read that can lead to a program crash, the leakage of sensitive data from memory, or the execution of arbitrary code in the current user’s process context. The weakness is a classic out‑of‑range read (CWE‑125) and is scored as moderate severity with a CVSS of 5.3.

Affected Systems

The vulnerability affects Autodesk 3ds Max product lines following the 2026 release, including 2026 and 2027 variants, but no specific patch information is provided. Any installation of these edition versions that accepts SVG files is potentially impacted.

Risk and Exploitability

The CVSS score indicates a moderate risk of exploitation. Because the EPSS is not available and the vulnerability is not listed in the CISA KEV catalogue, the current data do not show a widely exploited threat. The attack path requires delivery of a malicious SVG file that is parsed by the application; it is therefore likely a local or user‑initiated vector unless an attacker can trigger the parsing remotely, such as via an upload or shared file scenario. The potential impact ranges from denial of service to arbitrary code execution depending on the content of the victim’s memory and execution context.

Generated by OpenCVE AI on August 24, 2026 at 22:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Acquire and install the latest Autodesk 3ds Max update that contains the fix for this SVG parsing issue.
  • Avoid opening or importing SVG files from untrusted or unknown sources into Autodesk 3ds Max.
  • Restrict the execution context of Autodesk 3ds Max by running it with least privilege and in a sandboxed environment where possible.
  • Monitor Autodesk security advisories for updated guidance or any changes to the status of this vulnerability.

Generated by OpenCVE AI on August 24, 2026 at 22:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:autodesk:3ds_max:*:*:*:*:*:*:*:*

Tue, 25 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 24 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
Title SVG File Parsing Out-of-Bounds Read Vulnerability in Autodesk 3ds Max
First Time appeared Autodesk
Autodesk 3ds Max
Weaknesses CWE-125
CPEs cpe:2.3:a:autodesk:3ds_max:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:3ds_max:2027:*:*:*:*:*:*:*
Vendors & Products Autodesk
Autodesk 3ds Max
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Autodesk 3ds Max
cve-icon MITRE

Status: PUBLISHED

Assigner: autodesk

Published:

Updated: 2026-08-25T14:51:55.740Z

Reserved: 2026-07-23T17:47:20.060Z

Link: CVE-2026-16782

cve-icon Vulnrichment

Updated: 2026-08-25T14:46:38.457Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-24T21:16:48.900

Modified: 2026-08-28T17:33:34.483

Link: CVE-2026-16782

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T23:00:06Z

Weaknesses