CVE-2026-0537
Autodesk 3ds Max vulnerability analysis and mitigation

Overview

CVE-2026-0537 is a memory corruption vulnerability in Autodesk 3ds Max's RGB file parser that allows arbitrary code execution in the context of the current process. It affects Autodesk 3ds Max versions 2026 through 2026.3.1 (i.e., all 2026 releases prior to 2026.3.2). The vulnerability was published on February 4, 2026, with a patch made available shortly after. It carries a CVSS v3.1 base score of 8.4 (High) per NVD, or 7.8 (High) per the ENISA/Autodesk scoring that accounts for required user interaction (Autodesk Advisory, Red Hat CVE).

Technical details

The root cause is an out-of-bounds write (CWE-787) triggered during the parsing of a maliciously crafted RGB image file within Autodesk 3ds Max. When the application processes such a file, improper memory handling leads to a memory corruption condition that can be leveraged to redirect execution flow and run attacker-controlled code. Exploitation requires a user to open a malicious RGB file (user interaction), but no special privileges are needed. No public proof-of-concept or detailed technical write-up has been identified at this time (Autodesk Advisory, Red Hat CVE).

Impact

Successful exploitation allows an attacker to execute arbitrary code with the privileges of the user running Autodesk 3ds Max, resulting in high confidentiality, integrity, and availability impacts. This could enable unauthorized access to sensitive project files and system data, modification or deletion of files, and disruption of the application or underlying system. The attack is limited to the local context (the user must open a malicious file), but in creative or engineering environments where RGB files are routinely shared, the risk of social engineering-based delivery is meaningful (Autodesk Advisory).

Exploitation steps

  1. Craft malicious RGB file: An attacker creates a specially crafted RGB image file designed to trigger an out-of-bounds write in Autodesk 3ds Max's file parser, embedding a payload to redirect execution.
  2. Deliver the file: The attacker delivers the malicious RGB file to a target user via email attachment, file-sharing platform, or a compromised asset repository commonly used in 3D design workflows.
  3. Social engineering: The attacker convinces the target (e.g., a 3D artist or designer) to open the file in Autodesk 3ds Max, exploiting the trust placed in shared project assets.
  4. Trigger memory corruption: Upon parsing the malicious RGB file, 3ds Max performs an out-of-bounds write, corrupting memory in a controlled manner.
  5. Achieve code execution: The memory corruption condition is leveraged to redirect the instruction pointer and execute attacker-supplied shellcode or a payload in the context of the 3ds Max process, with the privileges of the logged-in user (Autodesk Advisory).

Indicators of compromise

  • File System: Unexpected RGB files in project directories or temp folders originating from external or untrusted sources; new or modified files created by the 3ds Max process in unusual locations.
  • Process: Unusual child processes spawned by the Autodesk 3ds Max process (e.g., cmd.exe, powershell.exe, curl, wget); unexpected network connections initiated by the 3ds Max process.
  • Network: Outbound connections from the 3ds Max process to unknown or suspicious external IP addresses or domains, particularly shortly after opening an RGB file.
  • Logs: Application crash logs or Windows Event Logs indicating access violations or heap corruption in the 3ds Max process; unexpected process creation events logged by EDR solutions tied to the 3ds Max executable.

Mitigation and workarounds

Autodesk has released a patch in version 2026.3.2, which resolves this vulnerability. Users should update Autodesk 3ds Max 2026 to version 2026.3.2 or later as the primary remediation. Until patching is complete, users should avoid opening RGB files from untrusted or unverified sources, and administrators should consider restricting file sharing of RGB assets from external parties. Implementing application-level monitoring for unusual process behavior from 3ds Max is also recommended as a compensating control (Autodesk Advisory).

Community reactions

The vulnerability received routine coverage from vulnerability tracking services and security feeds shortly after disclosure, including mentions on Mastodon via TheHackerWire and aggregation by platforms such as VulDB, CVEFeed, and RedPacket Security. No significant vendor statements beyond the Autodesk security advisory, nor notable independent researcher commentary or media investigations, have been identified for this CVE (Autodesk Advisory).

Additional resources


SourceThis report was generated using AI

Related Autodesk 3ds Max vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-7454HIGH7.8
  • Autodesk 3ds Max logoAutodesk 3ds Max
  • cpe:2.3:a:autodesk:3ds_max
NoYesMay 26, 2026
CVE-2026-7452HIGH7.8
  • Autodesk 3ds Max logoAutodesk 3ds Max
  • cpe:2.3:a:autodesk:3ds_max
NoYesMay 26, 2026
CVE-2026-7451HIGH7.8
  • Autodesk 3ds Max logoAutodesk 3ds Max
  • cpe:2.3:a:autodesk:3ds_max
NoYesMay 26, 2026
CVE-2026-7453MEDIUM5.5
  • Autodesk 3ds Max logoAutodesk 3ds Max
  • cpe:2.3:a:autodesk:3ds_max
NoYesMay 26, 2026
CVE-2026-7450MEDIUM5.5
  • Autodesk 3ds Max logoAutodesk 3ds Max
  • cpe:2.3:a:autodesk:3ds_max
NoYesMay 26, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management