CVE-2026-0661
Autodesk 3ds Max vulnerability analysis and mitigation

Overview

CVE-2026-0661 is a memory corruption vulnerability in Autodesk 3ds Max triggered by parsing a maliciously crafted RGB file, enabling arbitrary code execution in the context of the current process. It affects Autodesk 3ds Max versions 2026 through 2026.3.1 (i.e., versions starting from 2026 up to but not including 2026.3.2). The vulnerability was published on February 4, 2026, with a patch advisory released shortly after. It carries a CVSS v3.1 base score of 8.4 (High) per NVD, and 7.8 (High) per the ENISA/Autodesk scoring (Autodesk Advisory, Red Hat CVE).

Technical details

The root cause is classified as CWE-787 (Out-of-bounds Write): when Autodesk 3ds Max parses a specially crafted RGB image file, it writes data beyond the bounds of an allocated memory buffer, resulting in memory corruption. This local attack vector requires no special privileges, though the ENISA/Autodesk scoring notes that user interaction (opening a malicious file) is required. An attacker would need to convince a target user to open a weaponized RGB file, after which the out-of-bounds write can be leveraged to redirect execution flow and run arbitrary code with the privileges of the 3ds Max process (Autodesk Advisory, Red Hat CVE).

Impact

Successful exploitation allows an attacker to execute arbitrary code with the privileges of the user running Autodesk 3ds Max, resulting in high confidentiality, integrity, and availability impact. This could lead to complete compromise of the application context, theft of sensitive project or design data, system manipulation, and potential lateral movement within the affected environment. The scope is limited to the current process context, but the full triad of CIA impacts is affected (Autodesk Advisory).

Exploitation steps

  1. Craft malicious RGB file: An attacker creates a specially crafted RGB image file designed to trigger an out-of-bounds write when parsed by Autodesk 3ds Max's RGB file parser.
  2. Deliver the file: The attacker delivers the malicious RGB file to a target user via email attachment, file-sharing platform, or by hosting it on a compromised or attacker-controlled website, using social engineering to prompt the user to open it.
  3. User opens the file: The target user opens the malicious RGB file in Autodesk 3ds Max (versions 2026 through 2026.3.1).
  4. Trigger memory corruption: The RGB parser writes data out of bounds, corrupting adjacent memory structures within the 3ds Max process.
  5. Achieve code execution: The memory corruption is leveraged to redirect execution flow, allowing the attacker to execute arbitrary code with the privileges of the current 3ds Max user process, enabling data theft, persistence, or further lateral movement (Autodesk Advisory).

Indicators of compromise

  • File System: Unexpected or suspicious .rgb files in user download directories, temp folders, or email attachment staging areas; unusual files written to disk by the 3ds Max process.
  • Process: Unexpected child processes spawned by the Autodesk 3ds Max executable (e.g., cmd.exe, powershell.exe, curl, or other shells/utilities); 3ds Max process crashing or exhibiting abnormal behavior upon opening an RGB file.
  • Logs: Application crash logs or Windows Event Logs (Event ID 1000/1001) referencing Autodesk 3ds Max with faulting module related to RGB file parsing; unexpected process creation events originating from the 3ds Max process.
  • Network: Outbound network connections initiated by the 3ds Max process to unknown or suspicious external IP addresses following the opening of an RGB file.

Mitigation and workarounds

Autodesk has released a patch in version 2026.3.2, which resolves this vulnerability. Users running Autodesk 3ds Max 2026 through 2026.3.1 should update to version 2026.3.2 or later immediately. As interim mitigations, restrict users from opening RGB files from untrusted or unknown sources, implement application whitelisting, and educate users about the risks of opening files from unverified origins. Monitor for suspicious process behavior associated with 3ds Max installations (Autodesk Advisory).

Community reactions

Coverage of CVE-2026-0661 has been limited to automated vulnerability tracking platforms and aggregators such as VulnDB, CVEFeed, RedPacket Security, and Tenable's plugin pipeline. No notable independent researcher commentary, vendor statements beyond the official Autodesk advisory, or significant social media discussion has been identified. The vulnerability received brief mention on Bluesky via The Hacker Wire's automated CVE feed (Autodesk Advisory).

Additional resources


SourceThis report was generated using AI

Related Autodesk 3ds Max vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-7454HIGH7.8
  • Autodesk 3ds Max logoAutodesk 3ds Max
  • cpe:2.3:a:autodesk:3ds_max
NoYesMay 26, 2026
CVE-2026-7452HIGH7.8
  • Autodesk 3ds Max logoAutodesk 3ds Max
  • cpe:2.3:a:autodesk:3ds_max
NoYesMay 26, 2026
CVE-2026-7451HIGH7.8
  • Autodesk 3ds Max logoAutodesk 3ds Max
  • cpe:2.3:a:autodesk:3ds_max
NoYesMay 26, 2026
CVE-2026-7453MEDIUM5.5
  • Autodesk 3ds Max logoAutodesk 3ds Max
  • cpe:2.3:a:autodesk:3ds_max
NoYesMay 26, 2026
CVE-2026-7450MEDIUM5.5
  • Autodesk 3ds Max logoAutodesk 3ds Max
  • cpe:2.3:a:autodesk:3ds_max
NoYesMay 26, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management