
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-7451 is an Out-of-Bounds Write vulnerability in Autodesk 3ds Max triggered by parsing a maliciously crafted TIF file. It affects Autodesk 3ds Max versions 2026 (prior to 2026.1) and 2027 (prior to 2027.1). The vulnerability was published on May 26, 2026, and carries a CVSS v3.1 base score of 7.8 (High) (Autodesk Advisory, GitHub Advisory).
The vulnerability is classified as CWE-787 (Out-of-Bounds Write), occurring when Autodesk 3ds Max improperly handles a specially crafted TIF image file during parsing, writing data beyond the bounds of an allocated buffer. The attack vector is local, requiring no privileges but necessitating user interaction — specifically, a victim must open a malicious TIF file. Exploitation could be achieved via social engineering, phishing, or delivering a crafted file through shared network resources or email attachments (Autodesk Advisory, GitHub Advisory).
Successful exploitation can result in application crashes (denial of service), data corruption, or arbitrary code execution within the context of the user running Autodesk 3ds Max. All three security pillars are affected at a high level: confidentiality, integrity, and availability. An attacker who achieves code execution gains the same privileges as the victim user, potentially enabling access to sensitive project files, credentials stored on the system, or further lateral movement within the local network (Autodesk Advisory, GitHub Advisory).
3dsmax.exe) crashing unexpectedly or spawning unusual child processes (e.g., cmd.exe, powershell.exe, curl.exe) after opening a TIF file.3dsmax.exe; Dr. Watson or Windows Error Reporting entries referencing memory access violations in the 3ds Max process.3dsmax.exe to external IP addresses following file open events.Autodesk has released patched versions addressing this vulnerability: 3ds Max 2026.1 and 3ds Max 2027.1. Users should update immediately via Autodesk Access or the Autodesk desktop app (Autodesk Advisory). As interim mitigations, organizations should restrict users from opening TIF files from untrusted or unknown sources, implement email attachment filtering for TIF files where feasible, and educate users about the risks of opening files from unverified sources.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."