Description
A maliciously crafted ABC file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
Published: 2026-08-24
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

When Autodesk 3ds Max parses a maliciously crafted ABC file, an out‑of‑bounds write occurs that can crash the application, corrupt data, or execute arbitrary code in the context of the running process. This flaw is a classic uncontrolled write beyond buffer limits (CWE‑787).

Affected Systems

The vulnerability impacts Autodesk 3ds Max 2026 and 2027 releases. Any installation of these editions that accepts ABC files for editing or rendering can be affected. No other vendors or products are listed.

Risk and Exploitability

The flaw has a CVSS score of 7.8, indicating high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack requires a malicious ABC file to be processed by 3ds Max, so the most likely vector is a local user opening the file or the file being delivered via a shared network location. Because the exploit can lead to arbitrary code execution, organizations should treat it as high risk until an official patch or corrective action is applied. Organizations should monitor for abnormal crashes and memory corruption signs, and consider restricting file access paths until mitigations are in place.

Generated by OpenCVE AI on August 24, 2026 at 22:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Autodesk 3ds Max patch that addresses the AB file parsing flaw.
  • Restrict the ability of end users to open ABC files from untrusted locations; consider disabling the ABC file importer or confining it to a sandboxed environment.
  • Enforce stringent file‑level access controls on directories where 3ds Max reads ABC files to prevent malicious file placement.
  • If no fix is immediately available, monitor 3ds Max logs for abnormal memory writes or crashes and apply endpoint protection capable of blocking out‑of‑bounds write exploits.

Generated by OpenCVE AI on August 24, 2026 at 22:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:autodesk:3ds_max:*:*:*:*:*:*:*:*

Tue, 25 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 24 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description A maliciously crafted ABC file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
Title ABC File Parsing Out-of-Bounds Write Vulnerability in Autodesk 3ds Max
First Time appeared Autodesk
Autodesk 3ds Max
Weaknesses CWE-787
CPEs cpe:2.3:a:autodesk:3ds_max:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:3ds_max:2027:*:*:*:*:*:*:*
Vendors & Products Autodesk
Autodesk 3ds Max
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Autodesk 3ds Max
cve-icon MITRE

Status: PUBLISHED

Assigner: autodesk

Published:

Updated: 2026-08-26T03:56:07.890Z

Reserved: 2026-07-23T17:47:20.712Z

Link: CVE-2026-16783

cve-icon Vulnrichment

Updated: 2026-08-25T19:05:50.066Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-24T21:16:49.023

Modified: 2026-08-28T17:33:24.437

Link: CVE-2026-16783

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T00:30:03Z

Weaknesses