Description
A maliciously crafted FLT file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
Published: 2026-08-24
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Assess Impact
AI Analysis

Impact

A maliciously crafted FLT file, when parsed by Autodesk 3ds Max, triggers an out‑of‑bounds write that can corrupt memory or allow an attacker to execute arbitrary code in the process context. The flaw is a classic buffer overrun (CWE‑787) and can lead to application crashes, data corruption, or compromise of the host system if exploited.

Affected Systems

The vulnerability affects Autodesk 3ds Max versions 2026 and 2027. Any deployment of these products that processes external FLT files may be impacted. The vendor is Autodesk, and the affected product is 3ds Max.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity, but the EPSS score is not available, making it unclear how frequently this flaw is exploited in the wild. The flaw is not listed in the CISA KEV catalog. Attackers would need to supply a crafted FLT file that the user opens or that is processed automatically, so the risk is primarily for users who import untrusted files or for systems that allow automated import of FLT data.

Generated by OpenCVE AI on August 24, 2026 at 23:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Verify whether a vendor patch or update addressing the FLT parsing overrun is available for your 3ds Max version and apply it if found.
  • Restrict or monitor the use of FLT files from untrusted sources and avoid opening them in the affected software.
  • Implement application whitelisting or sandboxing for 3ds Max to contain potential exploitation.

Generated by OpenCVE AI on August 24, 2026 at 23:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:autodesk:3ds_max:*:*:*:*:*:*:*:*

Tue, 25 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 24 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description A maliciously crafted FLT file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
Title FLT File Parsing Out-of-Bounds Write Vulnerability in Autodesk 3ds Max
First Time appeared Autodesk
Autodesk 3ds Max
Weaknesses CWE-787
CPEs cpe:2.3:a:autodesk:3ds_max:2026:*:*:*:*:*:*:*
cpe:2.3:a:autodesk:3ds_max:2027:*:*:*:*:*:*:*
Vendors & Products Autodesk
Autodesk 3ds Max
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Autodesk 3ds Max
cve-icon MITRE

Status: PUBLISHED

Assigner: autodesk

Published:

Updated: 2026-08-26T03:56:09.639Z

Reserved: 2026-04-29T17:19:14.865Z

Link: CVE-2026-7455

cve-icon Vulnrichment

Updated: 2026-08-25T19:05:29.695Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-24T21:17:49.040

Modified: 2026-08-28T17:33:13.870

Link: CVE-2026-7455

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T23:15:04Z

Weaknesses