Autodesk
Autodesk 3DS MAX: vulnerabilidades y CVE
Autodesk 3DS MAX tiene 29 vulnerabilidades publicadas, 19 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE29
Últimos 12 meses19
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-7455 | Alta (7.8) | 0.19% | — | 24 ago 2026 | A maliciously crafted FLT file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute… |
| CVE-2026-19568 | Alta (7.8) | 0.13% | — | 24 ago 2026 | A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the… |
| CVE-2026-16783 | Alta (7.8) | 0.13% | — | 24 ago 2026 | A maliciously crafted ABC file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute… |
| CVE-2026-16782 | Alta (7.8) | 0.21% | — | 24 ago 2026 | A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute… |
| CVE-2026-16781 | Media (5.5) | 0.11% | — | 24 ago 2026 | A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can trigger an Uncontrolled Recursion vulnerability. A malicious actor may leverage this vulnerability to cause the application to terminate… |
| CVE-2026-7454 | Alta (7.8) | 0.19% | — | 26 may 2026 | A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the… |
| CVE-2026-7453 | Media (5.5) | 0.16% | — | 26 may 2026 | A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can cause a Stack Exhaustion vulnerability, leading to a denial-of-service condition. |
| CVE-2026-7452 | Alta (7.8) | 0.19% | — | 26 may 2026 | A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the… |
| CVE-2026-7451 | Alta (7.8) | 0.19% | — | 26 may 2026 | A maliciously crafted TIF file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute… |
| CVE-2026-7450 | Media (5.5) | 0.16% | — | 26 may 2026 | A maliciously crafted PAR file, when parsed through Autodesk 3ds Max, can force a NULL Pointer Dereference vulnerability. Successful exploitation may cause the application to crash, leading to a denial-of-service… |
| CVE-2026-0536 | Alta (7.8) | 0.21% | — | 4 feb 2026 | A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can cause a Stack-Based Buffer Overflow vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of… |
| CVE-2026-0662 | Alta (7.8) | 0.21% | — | 4 feb 2026 | A maliciously crafted project directory, when opening a max file in Autodesk 3ds Max, could lead to execution of arbitrary code in the context of the current process due to an Untrusted Search Path being utilized. |
| CVE-2026-0661 | Alta (8.4) | 0.19% | — | 4 feb 2026 | A maliciously crafted RGB file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the… |
| CVE-2026-0660 | Alta (8.4) | 0.22% | — | 4 feb 2026 | A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can cause a Stack-Based Buffer Overflow vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of… |
| CVE-2026-0659 | Alta (7.8) | 0.24% | — | 4 feb 2026 | A maliciously crafted USD file, when loaded or imported into Autodesk Arnold or Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary… |
| CVE-2026-0538 | Alta (8.4) | 0.19% | — | 4 feb 2026 | A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the… |
| CVE-2026-0537 | Alta (8.4) | 0.19% | — | 4 feb 2026 | A maliciously crafted RGB file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the… |
| CVE-2025-11797 | Alta (7.8) | 0.16% | — | 12 nov 2025 | A maliciously crafted DWG file, when parsed through Autodesk 3ds Max, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute… |
| CVE-2025-11795 | Alta (7.8) | 0.17% | — | 12 nov 2025 | A maliciously crafted JPG file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the… |
| CVE-2025-6634 | Alta (7.8) | 0.20% | — | 6 ago 2025 | A maliciously crafted TGA file, when linked or imported into Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of… |
| CVE-2025-6633 | Alta (7.8) | 0.20% | — | 6 ago 2025 | A maliciously crafted RBG file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute… |
| CVE-2025-6632 | Alta (7.8) | 0.19% | — | 6 ago 2025 | A maliciously crafted PSD file, when linked or imported into Autodesk 3ds Max, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or… |
| CVE-2023-25002 | Alta (7.8) | 0.35% | — | 27 jun 2023 | A maliciously crafted SKP file in Autodesk products is used to trigger use-after-free vulnerability. Exploitation of this vulnerability may lead to code execution. |
| CVE-2022-25793 | Alta (7.8) | 0.39% | — | 10 ago 2022 | A Stack-based Buffer Overflow Vulnerability in Autodesk 3ds Max 2022, 2021, and 2020 may lead to code execution through the lack of proper validation of the length of user-supplied data prior to copying it to a… |
| CVE-2022-27871 | Alta (7.8) | 0.76% | — | 21 jun 2022 | Autodesk AutoCAD product suite, Revit, Design Review and Navisworks releases using PDFTron prior to 9.1.17 version may be used to write beyond the allocated buffer while parsing PDF files. This vulnerability may be… |
| CVE-2022-27532 | Alta (7.8) | 1.0% | — | 16 jun 2022 | A maliciously crafted TIF file in Autodesk 3ds Max 2022 and 2021 can be used to write beyond the allocated buffer while parsing TIF files. This vulnerability in conjunction with other vulnerabilities could lead to… |
| CVE-2022-27531 | Alta (7.8) | 0.78% | — | 16 jun 2022 | A maliciously crafted TIF file can be forced to read beyond allocated boundaries in Autodesk 3ds Max 2022, and 2021 when parsing the TIF files. This vulnerability in conjunction with other vulnerabilities could lead to… |
| CVE-2009-3577 | Alta (9.3) | 5.1% | — | 24 nov 2009 | Autodesk 3D Studio Max (3DSMax) 6 through 9 and 2008 through 2010 allows remote attackers to execute arbitrary code via a .max file with a MAXScript statement that calls the DOSCommand method, related to "application… |
| CVE-2005-4710 | Media (4.6) | 0.59% | — | 31 dic 2005 | Unspecified vulnerability in multiple Autodesk and AutoCAD products and product families from 2006 and earlier allows remote attackers to "gain inappropriate access to another local user's computer," aka ID DL5549329. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.