CVE-2025-11797

7.8

Autodesk · 3ds Max

A Use-After-Free vulnerability in Autodesk 3ds Max allows a malicious DWG file to trigger a crash, read sensitive data, or execute arbitrary code.

Executive summary

A critical Use-After-Free vulnerability in Autodesk 3ds Max enables unauthorized code execution when a user opens a specially crafted DWG file.

Vulnerability

This is a Use-After-Free (CWE-416) flaw triggered by the parsing of malicious DWG files. The vulnerability requires user interaction to open the file, but it does not require authentication to trigger.

Business impact

The exploitation of this vulnerability could lead to a complete compromise of the host system, including the theft of intellectual property or unauthorized access to sensitive project data. Given the CVSS score of 7.8, this represents a high-severity risk that could result in significant operational disruption and data loss if an attacker succeeds in executing arbitrary code within the context of the 3ds Max process.

Remediation

Immediate Action: Update Autodesk 3ds Max to version 2026.3 or later as specified in the official vendor advisory to resolve the underlying flaw.

Proactive Monitoring: Monitor workstation security logs for unexpected process crashes or suspicious child processes spawned by the 3ds Max application.

Compensating Controls: Implement strict file-handling policies that restrict the opening of DWG files from untrusted or external sources until the software has been patched.

Exploitation status

Public Exploit Available: No — exploit_available (false).

Analyst recommendation

The risk associated with this vulnerability is high due to the potential for arbitrary code execution. Organizations should prioritize updating all instances of Autodesk 3ds Max 2026 to version 2026.3 immediately to eliminate the possibility of exploitation via malicious DWG files.

More Autodesk CVEs

Sources