CVE-2026-16783

7.8

Autodesk · 3ds Max

Autodesk 3ds Max is susceptible to an out-of-bounds write vulnerability when parsing maliciously crafted ABC files, potentially leading to arbitrary code execution.

Executive summary

A memory corruption vulnerability in Autodesk 3ds Max allows an attacker to execute arbitrary code by supplying a specially crafted ABC file.

Vulnerability

This is an out-of-bounds write vulnerability (CWE-787) triggered when the software parses an malformed ABC file. An attacker must convince a user to open a malicious file, at which point the application may crash or execute arbitrary code with the user's privileges.

Business impact

The ability to execute arbitrary code via a malicious file presents a significant risk to workstations running 3ds Max. With a CVSS score of 7.8, this vulnerability could facilitate unauthorized access to sensitive project files or lead to complete system compromise if the user possesses elevated permissions.

Remediation

Immediate Action: Update Autodesk 3ds Max to the versions specified in the vendor security advisory (ADSK-SA-2026-0014) to resolve the memory handling flaw.

Proactive Monitoring: Review file access logs and implement endpoint detection to identify suspicious file parsing activity or unexpected application crashes.

Compensating Controls: Exercise caution when opening files from untrusted sources and utilize security software that scans external files before they are parsed by 3ds Max.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Users and administrators should prioritize applying the latest security updates provided by Autodesk. Given the high impact of arbitrary code execution, all instances of 3ds Max within the organization must be patched to the recommended versions.

More Autodesk CVEs