Impact
A maliciously crafted FLT file, when parsed by Autodesk 3ds Max, triggers an out‑of‑bounds write that can corrupt memory or allow an attacker to execute arbitrary code in the process context. The flaw is a classic buffer overrun (CWE‑787) and can lead to application crashes, data corruption, or compromise of the host system if exploited.
Affected Systems
The vulnerability affects Autodesk 3ds Max versions 2026 and 2027. Any deployment of these products that processes external FLT files may be impacted. The vendor is Autodesk, and the affected product is 3ds Max.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, but the EPSS score is not available, making it unclear how frequently this flaw is exploited in the wild. The flaw is not listed in the CISA KEV catalog. Attackers would need to supply a crafted FLT file that the user opens or that is processed automatically, so the risk is primarily for users who import untrusted files or for systems that allow automated import of FLT data.
OpenCVE Enrichment