CVE-2026-7455

7.8

Autodesk · 3ds Max

Autodesk 3ds Max is vulnerable to an out of bounds write when parsing a maliciously crafted FLT file, potentially leading to arbitrary code execution.

Executive summary

A high severity out of bounds write vulnerability in Autodesk 3ds Max could allow an attacker to execute arbitrary code via a specially crafted FLT file.

Vulnerability

This is an out of bounds write vulnerability (CWE-787) triggered when the application parses a malformed FLT file. The attack vector is local, requiring a user to open a malicious file, and does not require prior authentication.

Business impact

Successful exploitation of this vulnerability could lead to a full system compromise, as the flaw allows for arbitrary code execution with the privileges of the user running the software. Given the CVSS score of 7.8, this poses a significant risk to organizational assets, potentially resulting in unauthorized data access or the installation of persistent malicious software within the design environment.

Remediation

Immediate Action: Update Autodesk 3ds Max to version 2027.2.0 or 2026.3.4, or the latest available version provided in the official security advisory.

Proactive Monitoring: Monitor workstation endpoints for unusual process executions or unauthorized attempts to access sensitive directories following the opening of design files.

Compensating Controls: Ensure that users operate with the least privilege necessary, and avoid opening untrusted or unsolicited FLT files from external sources.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

The risk posed by this memory corruption vulnerability is high due to its potential for remote code execution. Administrators should prioritize the deployment of the vendor patches to all affected workstations to prevent potential system exploitation.

More Autodesk CVEs