CVE-2026-7450
Autodesk 3ds Max vulnerability analysis and mitigation

Overview

CVE-2026-7450 is a NULL Pointer Dereference vulnerability in Autodesk 3ds Max triggered by parsing a maliciously crafted PAR file, resulting in a denial-of-service condition via application crash. It affects Autodesk 3ds Max versions 2026 (prior to 2026.1) and 2027 (prior to 2027.1). The vulnerability was published on May 26, 2026, with a patch made available the same day. It carries a CVSS v3.1 base score of 5.5 (Medium) per NVD, and 5.3 (Medium) per the GitHub Advisory Database (GitHub Advisory, Autodesk Advisory).

Technical details

The root cause is classified as CWE-476 (NULL Pointer Dereference), where the PAR file parser in Autodesk 3ds Max fails to validate a pointer before dereferencing it, leading to an unhandled null dereference. The attack vector is local (AV:L), requiring no privileges but necessitating user interaction — specifically, a user must open a specially crafted PAR file within the application. No public proof-of-concept exploit code has been identified at this time (GitHub Advisory, Autodesk Advisory).

Impact

Successful exploitation causes Autodesk 3ds Max to crash, resulting in a denial-of-service condition that disrupts availability for the affected user. There is no impact on confidentiality or integrity under the NVD scoring, though the EUVD/GitHub Advisory notes low confidentiality, integrity, and availability impacts under an alternate vector. The scope is limited to the local application instance and does not facilitate lateral movement or data exfiltration (GitHub Advisory, Autodesk Advisory).

Exploitation steps

  1. Craft a malicious PAR file: An attacker creates a specially crafted PAR (particle system or parameter) file designed to trigger a null pointer dereference when parsed by Autodesk 3ds Max's file parser.
  2. Deliver the file to the target: The attacker distributes the malicious PAR file to a target user via email attachment, file sharing, or by placing it in a shared directory accessible to the victim.
  3. Induce user interaction: The attacker social-engineers the victim into opening the crafted PAR file within Autodesk 3ds Max (e.g., by disguising it as a legitimate project asset).
  4. Trigger the crash: Upon parsing the malformed PAR file, 3ds Max dereferences a null pointer, causing an unhandled exception and crashing the application, achieving a denial-of-service condition (GitHub Advisory, Autodesk Advisory).

Indicators of compromise

  • File System: Presence of unexpected or unsolicited .par files in project directories or user download folders, particularly those received from external or untrusted sources.
  • Logs: Application crash logs or Windows Event Viewer entries (Event ID 1000/1001) referencing 3dsmax.exe with a faulting module related to PAR file parsing; crash dump files (.dmp) generated in the 3ds Max application directory.
  • Process: Unexpected termination of the 3dsmax.exe process shortly after opening a PAR file, with no user-initiated close action.

Mitigation and workarounds

Autodesk has released patched versions: 3ds Max 2026.1 and 3ds Max 2027.1. Users should update immediately via Autodesk Access or the Autodesk desktop application. As a workaround, organizations should restrict PAR file handling to trusted sources only and educate users about the risks of opening files from unknown or untrusted origins (Autodesk Advisory, GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related Autodesk 3ds Max vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-7454HIGH7.8
  • Autodesk 3ds Max logoAutodesk 3ds Max
  • cpe:2.3:a:autodesk:3ds_max
NoYesMay 26, 2026
CVE-2026-7452HIGH7.8
  • Autodesk 3ds Max logoAutodesk 3ds Max
  • cpe:2.3:a:autodesk:3ds_max
NoYesMay 26, 2026
CVE-2026-7451HIGH7.8
  • Autodesk 3ds Max logoAutodesk 3ds Max
  • cpe:2.3:a:autodesk:3ds_max
NoYesMay 26, 2026
CVE-2026-7453MEDIUM5.5
  • Autodesk 3ds Max logoAutodesk 3ds Max
  • cpe:2.3:a:autodesk:3ds_max
NoYesMay 26, 2026
CVE-2026-7450MEDIUM5.5
  • Autodesk 3ds Max logoAutodesk 3ds Max
  • cpe:2.3:a:autodesk:3ds_max
NoYesMay 26, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management