Impact
A maliciously crafted SVG file, when parsed by Autodesk 3ds Max, can cause memory corruption that lets an attacker execute arbitrary code in the context of the current process. This flaw is a classic buffer overrun (CWE-120) and results in a high‑severity risk due to the possibility of full control of the local application. Since it can be triggered by simply opening a bad file, the attack surface is broad and any user who can import SVG content is potentially vulnerable.
Affected Systems
Autodesk 3ds Max 2026 and 2027 are affected. No other versions or products are listed, so only these releases require attention.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity. EPSS is unavailable, so the current exploit probability cannot be quantified, but the lack of KEV listing suggests no publicly known exploits yet. The vulnerability can be leveraged by any user who loads a malicious SVG; the attacker only needs to supply a crafted file, which is easily created. Therefore, the risk is significant, and mitigations should be applied promptly.
OpenCVE Enrichment