CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

autodesk

3ds_max

16 known vulnerabilities · sorted by CVSS score

CVE-2022-25793
HIGH7.8

A Stack-based Buffer Overflow Vulnerability in Autodesk 3ds Max 2022, 2021, and 2020 may lead to code execution through the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer when parsing ActionScript Byte Code files. This vulnerability may allow arbitrary code execution on affected installations of Autodesk 3ds Max.

autodesk / 3ds_max+2
Local
Published Aug 10, 2022
CVE-2025-11795
HIGH7.8

A maliciously crafted JPG file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

autodesk / 3ds_max
Local
Published Nov 12, 2025
CVE-2022-27531
HIGH7.8

A maliciously crafted TIF file can be forced to read beyond allocated boundaries in Autodesk 3ds Max 2022, and 2021 when parsing the TIF files. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

autodesk / 3ds_max+1
Local
Published Jun 16, 2022
CVE-2026-0537
HIGH7.8

A maliciously crafted RGB file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

autodesk / 3ds_max
Local
Published Feb 4, 2026
CVE-2025-11797
HIGH7.8

A maliciously crafted DWG file, when parsed through Autodesk 3ds Max, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

autodesk / 3ds_max
Local
Published Nov 12, 2025
CVE-2022-27532
HIGH7.8

A maliciously crafted TIF file in Autodesk 3ds Max 2022 and 2021 can be used to write beyond the allocated buffer while parsing TIF files. This vulnerability in conjunction with other vulnerabilities could lead to arbitrary code execution.

autodesk / 3ds_max+1
Local
Published Jun 16, 2022
CVE-2025-6634
HIGH7.8

A maliciously crafted TGA file, when linked or imported into Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

autodesk / 3ds_max
Local
Published Aug 6, 2025
CVE-2026-0660
HIGH7.8

A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can cause a Stack-Based Buffer Overflow vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

autodesk / 3ds_max
Local
Published Feb 4, 2026
CVE-2026-0536
HIGH7.8

A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can cause a Stack-Based Buffer Overflow vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

autodesk / 3ds_max
Local
Published Feb 4, 2026
CVE-2026-0538
HIGH7.8

A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

autodesk / 3ds_max
Local
Published Feb 4, 2026
CVE-2023-25002
HIGH7.8

A maliciously crafted SKP file in Autodesk products is used to trigger use-after-free vulnerability. Exploitation of this vulnerability may lead to code execution.

autodesk / 3ds_max+6
Local
Published Jun 27, 2023
CVE-2025-6633
HIGH7.8

A maliciously crafted RBG file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.

autodesk / 3ds_max
Local
Published Aug 6, 2025
CVE-2026-0661
HIGH7.8

A maliciously crafted RGB file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

autodesk / 3ds_max
Local
Published Feb 4, 2026
CVE-2022-27871
HIGH7.8

Autodesk AutoCAD product suite, Revit, Design Review and Navisworks releases using PDFTron prior to 9.1.17 version may be used to write beyond the allocated buffer while parsing PDF files. This vulnerability may be exploited to execute arbitrary code.

autodesk / 3ds_max+50
Local
Published Jun 21, 2022
CVE-2026-0662
HIGH7.8

A maliciously crafted project directory, when opening a max file in Autodesk 3ds Max, could lead to execution of arbitrary code in the context of the current process due to an Untrusted Search Path being utilized.

autodesk / 3ds_max
Local
Published Feb 4, 2026
CVE-2025-6632
MEDIUM5.3

A maliciously crafted PSD file, when linked or imported into Autodesk 3ds Max, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

autodesk / 3ds_max
Local
Published Aug 6, 2025