CVE-2026-19568

7.8

Autodesk · 3ds Max

Autodesk 3ds Max is vulnerable to memory corruption when parsing malformed SVG files, which may allow an attacker to execute arbitrary code.

Executive summary

Autodesk 3ds Max contains a memory corruption vulnerability that can be triggered by a malicious SVG file, posing a risk of arbitrary code execution.

Vulnerability

This vulnerability, categorized as CWE-120, involves a buffer overflow condition occurring during the parsing of SVG files. An attacker can leverage this flaw to corrupt memory and potentially execute arbitrary code by providing a specially crafted file to a user.

Business impact

Exploitation of this vulnerability could lead to unauthorized system access and potential loss of intellectual property stored within the 3ds Max environment. The CVSS score of 7.8 reflects the high risk associated with memory corruption vulnerabilities that can be weaponized through common file formats.

Remediation

Immediate Action: Apply the security updates provided by Autodesk in advisory ADSK-SA-2026-0014 to patch the affected versions of 3ds Max.

Proactive Monitoring: Monitor for application instability or unusual memory consumption patterns when the software is parsing complex or external SVG files.

Compensating Controls: Implement strict file-handling policies that require scanning of all imported assets from external or untrusted origins.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

The technical risk posed by this memory corruption flaw is substantial. Administrators must ensure that all Autodesk 3ds Max installations are updated according to the vendor's instructions to prevent potential exploitation.

More Autodesk CVEs