
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-0660 is a Stack-Based Buffer Overflow vulnerability in Autodesk 3ds Max's GIF file parser (CWE-121) that allows arbitrary code execution when a maliciously crafted GIF file is opened. It affects Autodesk 3ds Max versions 2026 through versions prior to 2026.3.2. The vulnerability was published on February 4, 2026, with a patch made available shortly after. It carries a CVSS v3.1 base score of 8.4 (High) per NVD, or 7.8 (High) per ENISA/EUVD scoring (Autodesk Advisory, Red Hat CVE).
The root cause is a stack-based buffer overflow (CWE-121) triggered during the parsing of a specially crafted GIF image file within Autodesk 3ds Max. When the application processes the malformed GIF, insufficient bounds checking on stack-allocated buffers allows an attacker to overwrite adjacent memory, redirecting execution flow to attacker-controlled code. The attack vector is local, requiring the target user to open or import a malicious GIF file within 3ds Max. No public proof-of-concept exploit code has been identified at this time (Autodesk Advisory).
Successful exploitation allows an attacker to execute arbitrary code in the context of the Autodesk 3ds Max process, which runs with the privileges of the logged-in user. This can result in full compromise of the affected workstation, including unauthorized access to sensitive design files and intellectual property, modification or deletion of data, and disruption of application availability. Depending on the user's privilege level and network environment, lateral movement within the organization may also be possible (Autodesk Advisory, Red Hat CVE).
cmd.exe, powershell.exe, curl, wget); 3ds Max crashing or terminating unexpectedly after opening a GIF file.Autodesk has released a patch in version 2026.3.2, which resolves this vulnerability. Users running Autodesk 3ds Max 2026 (any version prior to 2026.3.2) should upgrade immediately. As interim mitigations, users should avoid opening GIF files from untrusted or unknown sources within 3ds Max, implement application whitelisting, and conduct user awareness training on social engineering risks. Organizations should also monitor 3ds Max processes for anomalous behavior using endpoint detection and response (EDR) tools (Autodesk Advisory).
Coverage of CVE-2026-0660 has been limited to automated vulnerability tracking platforms and security news aggregators such as RedPacket Security, The Hacker Wire, and CVE feed services. No notable independent researcher commentary or significant social media discussion has been identified. Red Hat has also catalogued the vulnerability in their security advisory database (Red Hat CVE).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."