CVE-2025-6633

8.3

Autodesk · 3ds Max

A maliciously crafted RBG file parsed by Autodesk 3ds Max can trigger an out-of-bounds write vulnerability, potentially leading to arbitrary code execution.

Executive summary

Autodesk 3ds Max is affected by an out-of-bounds write vulnerability that could allow an attacker to execute arbitrary code or cause system instability.

Vulnerability

This vulnerability is an out-of-bounds write (CWE-787) flaw triggered when the application processes a specially crafted RBG file. The attack vector is local, requiring user interaction to open the malicious file, and does not require pre-existing authentication.

Business impact

The exploitation of this vulnerability can lead to unauthorized code execution within the context of the user running the software, potentially resulting in complete system compromise. With a CVSS score of 8.3, this flaw poses a high risk to business operations, as it could facilitate the theft of sensitive project intellectual property or result in significant data corruption and service disruption.

Remediation

Immediate Action: Users must update to Autodesk 3ds Max version 2026.2 or later to apply the necessary security patches.

Proactive Monitoring: Security teams should monitor workstation logs for abnormal application crashes or unexpected file system activity associated with the 3ds Max process.

Compensating Controls: Implement strict file access controls and ensure that users only open RBG files from trusted, verified sources to prevent the inadvertent execution of malicious content.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the high CVSS score and the potential for arbitrary code execution, this vulnerability represents a significant risk to design and engineering environments. Administrators should prioritize the deployment of the vendor provided update across all affected workstations to ensure the integrity of the local environment and protect sensitive project data.

More Autodesk CVEs

Sources