
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-7452 is a memory corruption vulnerability in Autodesk 3ds Max triggered by parsing a maliciously crafted WRL (VRML World) file, enabling arbitrary code execution in the context of the current process. It affects Autodesk 3ds Max versions 2026 (prior to 2026.1) and 2027 (prior to 2027.1). The vulnerability was published on May 26, 2026, with a patch made available the same day. It carries a CVSS v3.1 base score of 7.8 (High) (GitHub Advisory, Autodesk Advisory).
The root cause is classified as CWE-120 (Buffer Copy without Checking Size of Input / Classic Buffer Overflow), where the WRL file parser in 3ds Max copies input data into a buffer without validating that the input size does not exceed the destination buffer's capacity. An attacker crafts a malicious WRL file with oversized or malformed data that, when parsed, overwrites adjacent memory regions, leading to memory corruption. Exploitation requires local access and user interaction — specifically, a victim must be socially engineered into opening the malicious file within 3ds Max. No public proof-of-concept code has been identified (GitHub Advisory, Autodesk Advisory).
Successful exploitation allows an attacker to execute arbitrary code with the privileges of the Autodesk 3ds Max process, resulting in high confidentiality, integrity, and availability impact on the affected system. An attacker could access sensitive project files, install malware, or disrupt the application entirely. Because the attack vector is local and requires user interaction, the blast radius is limited to the workstation running 3ds Max, though it could serve as a foothold for further lateral movement within a network (GitHub Advisory, Autodesk Advisory).
cmd.exe, powershell.exe, curl, mshta.exe); 3ds Max process crashing or terminating unexpectedly after opening a WRL file.3dsmax.exe) with faulting module related to WRL/VRML parsing; unexpected process creation events logged by EDR solutions originating from 3dsmax.exe.3dsmax.exe to unknown external IP addresses or domains, particularly shortly after a WRL file is opened.Autodesk has released patched versions 3ds Max 2026.1 and 3ds Max 2027.1 to address this vulnerability; users should update immediately via Autodesk Access or the Autodesk desktop app. As a workaround, organizations should restrict users from opening WRL files from untrusted or unverified sources, and consider removing or restricting the WRL file type association. User awareness training on the risks of opening files from unknown sources is also recommended (Autodesk Advisory, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."