CVE-2026-0662
Autodesk 3ds Max vulnerability analysis and mitigation

Overview

CVE-2026-0662 is an Untrusted Search Path (CWE-426) vulnerability in Autodesk 3ds Max that allows arbitrary code execution when a user opens a maliciously crafted project directory containing a .max file. The vulnerability affects Autodesk 3ds Max versions 2026 through 2026.3.2 (exclusive). It was published on February 4, 2026, with a patch made available on February 6, 2026. The CVSS v3.1 base score is 7.8 (High) (Autodesk Advisory, Red Hat CVE).

Technical details

The root cause is an Untrusted Search Path (CWE-426), mapped to CAPEC-38 (Leveraging/Manipulating Configuration File Search Paths) and MITRE ATT&CK technique T1574.007 (Path Interception by PATH Environment Variable). When Autodesk 3ds Max opens a .max file, it resolves dependent libraries or resources using a search path that can be influenced by the contents of the project directory. An attacker who controls the project directory can place a malicious DLL or executable in a location that the application searches before legitimate system paths, causing it to be loaded and executed. Exploitation requires user interaction — specifically, a victim must open the crafted .max file — but no privileges are required (Autodesk Advisory, Red Hat CVE).

Impact

Successful exploitation results in arbitrary code execution in the context of the current user process, yielding high confidentiality, integrity, and availability impact. An attacker can gain unauthorized access to sensitive data on the system, modify or delete files, and potentially use the compromised workstation as a pivot point for lateral movement within the network. The attack is local in vector, meaning the malicious project directory must be delivered to and opened by the victim, but the consequences are equivalent to full user-level system compromise (Autodesk Advisory).

Exploitation steps

  1. Craft malicious project directory: Create a directory containing a legitimate-looking .max file alongside a malicious DLL or executable named to match a library that Autodesk 3ds Max searches for during file loading (e.g., a plugin or helper DLL).
  2. Deliver the payload: Distribute the malicious project directory to the target via phishing email, file-sharing platform, USB drive, or a compromised shared network drive, disguising it as a legitimate 3ds Max project.
  3. Induce user interaction: Social-engineer the victim into opening the .max file within Autodesk 3ds Max (e.g., by presenting it as a client asset or template).
  4. Trigger untrusted search path: When 3ds Max opens the file, it searches the project directory for dependent resources before checking system paths, loading the attacker-supplied malicious binary.
  5. Achieve code execution: The malicious binary executes with the privileges of the 3ds Max process (typically the logged-in user), enabling the attacker to establish persistence, exfiltrate data, or move laterally within the network (Autodesk Advisory).

Indicators of compromise

  • File System: Unexpected DLL or executable files placed within .max project directories, particularly files with names matching known 3ds Max plugins or system libraries; newly created or modified files in the 3ds Max installation or user profile directories shortly after opening a .max file.
  • Process: Unusual child processes spawned by the 3dsmax.exe process (e.g., cmd.exe, powershell.exe, curl.exe, or unknown executables); DLLs loaded by 3ds Max from non-standard paths (e.g., project directories rather than the application's install directory).
  • Network: Unexpected outbound network connections originating from 3dsmax.exe to external IP addresses or domains, particularly shortly after a .max file is opened.
  • Logs: Windows Event Logs (e.g., Event ID 4688 or Sysmon Event ID 1) showing process creation with 3dsmax.exe as the parent and unexpected child processes; Sysmon Event ID 7 (Image Loaded) showing DLLs loaded from project directories.

Mitigation and workarounds

Autodesk has released a patch in version 2026.3.2; users running any 3ds Max 2026 version prior to 2026.3.2 should upgrade immediately (Autodesk Advisory). As interim workarounds, organizations should restrict users from opening .max files received from untrusted or unverified sources, and implement controls (e.g., application whitelisting, endpoint DLP) to prevent loading of unauthorized DLLs. User awareness training on the risks of opening files from unknown sources is also recommended.

Community reactions

Coverage of CVE-2026-0662 has been limited to automated vulnerability tracking platforms and security news aggregators such as The Hacker Wire, Red Packet Security, and Tenable's plugin pipeline. No notable independent researcher commentary or significant social media discussion has been identified beyond routine CVE publication notices (Red Hat CVE, Autodesk Advisory).

Additional resources


SourceThis report was generated using AI

Related Autodesk 3ds Max vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-7454HIGH7.8
  • Autodesk 3ds Max logoAutodesk 3ds Max
  • cpe:2.3:a:autodesk:3ds_max
NoYesMay 26, 2026
CVE-2026-7452HIGH7.8
  • Autodesk 3ds Max logoAutodesk 3ds Max
  • cpe:2.3:a:autodesk:3ds_max
NoYesMay 26, 2026
CVE-2026-7451HIGH7.8
  • Autodesk 3ds Max logoAutodesk 3ds Max
  • cpe:2.3:a:autodesk:3ds_max
NoYesMay 26, 2026
CVE-2026-7453MEDIUM5.5
  • Autodesk 3ds Max logoAutodesk 3ds Max
  • cpe:2.3:a:autodesk:3ds_max
NoYesMay 26, 2026
CVE-2026-7450MEDIUM5.5
  • Autodesk 3ds Max logoAutodesk 3ds Max
  • cpe:2.3:a:autodesk:3ds_max
NoYesMay 26, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management