Impact
When Autodesk 3ds Max parses a maliciously crafted ABC file, an out‑of‑bounds write occurs that can crash the application, corrupt data, or execute arbitrary code in the context of the running process. This flaw is a classic uncontrolled write beyond buffer limits (CWE‑787).
Affected Systems
The vulnerability impacts Autodesk 3ds Max 2026 and 2027 releases. Any installation of these editions that accepts ABC files for editing or rendering can be affected. No other vendors or products are listed.
Risk and Exploitability
The flaw has a CVSS score of 7.8, indicating high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack requires a malicious ABC file to be processed by 3ds Max, so the most likely vector is a local user opening the file or the file being delivered via a shared network location. Because the exploit can lead to arbitrary code execution, organizations should treat it as high risk until an official patch or corrective action is applied. Organizations should monitor for abnormal crashes and memory corruption signs, and consider restricting file access paths until mitigations are in place.
OpenCVE Enrichment