Impact
A maliciously crafted SVG file, when processed by Autodesk 3ds Max, triggers an out‑of‑bounds read that can lead to a program crash, the leakage of sensitive data from memory, or the execution of arbitrary code in the current user’s process context. The weakness is a classic out‑of‑range read (CWE‑125) and is scored as moderate severity with a CVSS of 5.3.
Affected Systems
The vulnerability affects Autodesk 3ds Max product lines following the 2026 release, including 2026 and 2027 variants, but no specific patch information is provided. Any installation of these edition versions that accepts SVG files is potentially impacted.
Risk and Exploitability
The CVSS score indicates a moderate risk of exploitation. Because the EPSS is not available and the vulnerability is not listed in the CISA KEV catalogue, the current data do not show a widely exploited threat. The attack path requires delivery of a malicious SVG file that is parsed by the application; it is therefore likely a local or user‑initiated vector unless an attacker can trigger the parsing remotely, such as via an upload or shared file scenario. The potential impact ranges from denial of service to arbitrary code execution depending on the content of the victim’s memory and execution context.
OpenCVE Enrichment