CVE-2025-6634
7.8Autodesk · 3ds Max
Autodesk 3ds Max is vulnerable to memory corruption via a maliciously crafted TGA file, which may allow an attacker to execute arbitrary code.
Executive summary
A memory corruption vulnerability in Autodesk 3ds Max allows local attackers to execute arbitrary code through the processing of malformed TGA files.
Vulnerability
This is a buffer overflow vulnerability (CWE-120) triggered when the application parses a specially crafted TGA file. The vulnerability requires user interaction, specifically the linking or importing of the malicious file, and can be triggered by an unauthenticated attacker.
Business impact
Successful exploitation of this memory corruption flaw can lead to the execution of arbitrary code within the context of the user process. Given the CVSS score of 7.8, this represents a high-severity risk that could result in full system compromise, data theft, or the installation of persistent malware on workstations running 3ds Max.
Remediation
Immediate Action: Update Autodesk 3ds Max to version 2026.2 or later to apply the necessary security patches.
Proactive Monitoring: Monitor system logs for unusual process execution patterns or crashes associated with 3ds Max file import operations.
Compensating Controls: Restrict the import of TGA files from untrusted or external sources until the software update is applied to all affected workstations.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Organizations utilizing Autodesk 3ds Max should prioritize the deployment of the 2026.2 update across all design and production environments. Given the potential for arbitrary code execution, this patch should be treated as a high-priority maintenance task to ensure the integrity of the local workstation environment and prevent potential lateral movement if a system is compromised.