
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-7450 is a NULL Pointer Dereference vulnerability in Autodesk 3ds Max triggered by parsing a maliciously crafted PAR file, resulting in a denial-of-service condition via application crash. It affects Autodesk 3ds Max versions 2026 (prior to 2026.1) and 2027 (prior to 2027.1). The vulnerability was published on May 26, 2026, with a patch made available the same day. It carries a CVSS v3.1 base score of 5.5 (Medium) per NVD, and 5.3 (Medium) per the GitHub Advisory Database (GitHub Advisory, Autodesk Advisory).
The root cause is classified as CWE-476 (NULL Pointer Dereference), where the PAR file parser in Autodesk 3ds Max fails to validate a pointer before dereferencing it, leading to an unhandled null dereference. The attack vector is local (AV:L), requiring no privileges but necessitating user interaction — specifically, a user must open a specially crafted PAR file within the application. No public proof-of-concept exploit code has been identified at this time (GitHub Advisory, Autodesk Advisory).
Successful exploitation causes Autodesk 3ds Max to crash, resulting in a denial-of-service condition that disrupts availability for the affected user. There is no impact on confidentiality or integrity under the NVD scoring, though the EUVD/GitHub Advisory notes low confidentiality, integrity, and availability impacts under an alternate vector. The scope is limited to the local application instance and does not facilitate lateral movement or data exfiltration (GitHub Advisory, Autodesk Advisory).
.par files in project directories or user download folders, particularly those received from external or untrusted sources.3dsmax.exe with a faulting module related to PAR file parsing; crash dump files (.dmp) generated in the 3ds Max application directory.3dsmax.exe process shortly after opening a PAR file, with no user-initiated close action.Autodesk has released patched versions: 3ds Max 2026.1 and 3ds Max 2027.1. Users should update immediately via Autodesk Access or the Autodesk desktop application. As a workaround, organizations should restrict PAR file handling to trusted sources only and educate users about the risks of opening files from unknown or untrusted origins (Autodesk Advisory, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."