CVE-2026-7452
Autodesk 3ds Max vulnerability analysis and mitigation

Overview

CVE-2026-7452 is a memory corruption vulnerability in Autodesk 3ds Max triggered by parsing a maliciously crafted WRL (VRML World) file, enabling arbitrary code execution in the context of the current process. It affects Autodesk 3ds Max versions 2026 (prior to 2026.1) and 2027 (prior to 2027.1). The vulnerability was published on May 26, 2026, with a patch made available the same day. It carries a CVSS v3.1 base score of 7.8 (High) (GitHub Advisory, Autodesk Advisory).

Technical details

The root cause is classified as CWE-120 (Buffer Copy without Checking Size of Input / Classic Buffer Overflow), where the WRL file parser in 3ds Max copies input data into a buffer without validating that the input size does not exceed the destination buffer's capacity. An attacker crafts a malicious WRL file with oversized or malformed data that, when parsed, overwrites adjacent memory regions, leading to memory corruption. Exploitation requires local access and user interaction — specifically, a victim must be socially engineered into opening the malicious file within 3ds Max. No public proof-of-concept code has been identified (GitHub Advisory, Autodesk Advisory).

Impact

Successful exploitation allows an attacker to execute arbitrary code with the privileges of the Autodesk 3ds Max process, resulting in high confidentiality, integrity, and availability impact on the affected system. An attacker could access sensitive project files, install malware, or disrupt the application entirely. Because the attack vector is local and requires user interaction, the blast radius is limited to the workstation running 3ds Max, though it could serve as a foothold for further lateral movement within a network (GitHub Advisory, Autodesk Advisory).

Exploitation steps

  1. Craft malicious WRL file: Create a specially crafted VRML World (.wrl) file containing oversized or malformed data fields designed to overflow a buffer in 3ds Max's WRL parser.
  2. Deliver the file: Use social engineering tactics (e.g., phishing email, malicious download link, or shared network drive) to deliver the malicious WRL file to a target user who has Autodesk 3ds Max 2026 or 2027 installed.
  3. Trigger parsing: Convince the victim to open the malicious WRL file in 3ds Max, initiating the vulnerable parsing routine.
  4. Memory corruption: The parser copies the oversized input into a fixed-size buffer without bounds checking, corrupting adjacent memory (stack or heap).
  5. Achieve code execution: The memory corruption is leveraged to redirect execution flow (e.g., overwriting a return address or function pointer), executing attacker-controlled shellcode or a payload in the context of the 3ds Max process (GitHub Advisory, Autodesk Advisory).

Indicators of compromise

  • File System: Unexpected WRL files received via email attachments, downloads, or shared drives; presence of new or modified executables in the 3ds Max installation directory or user profile directories following file open events.
  • Process: Unusual child processes spawned by the 3ds Max process (e.g., cmd.exe, powershell.exe, curl, mshta.exe); 3ds Max process crashing or terminating unexpectedly after opening a WRL file.
  • Logs: Application crash logs or Windows Event Log entries (Event ID 1000/1001) referencing 3ds Max (3dsmax.exe) with faulting module related to WRL/VRML parsing; unexpected process creation events logged by EDR solutions originating from 3dsmax.exe.
  • Network: Outbound network connections initiated by 3dsmax.exe to unknown external IP addresses or domains, particularly shortly after a WRL file is opened.

Mitigation and workarounds

Autodesk has released patched versions 3ds Max 2026.1 and 3ds Max 2027.1 to address this vulnerability; users should update immediately via Autodesk Access or the Autodesk desktop app. As a workaround, organizations should restrict users from opening WRL files from untrusted or unverified sources, and consider removing or restricting the WRL file type association. User awareness training on the risks of opening files from unknown sources is also recommended (Autodesk Advisory, GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related Autodesk 3ds Max vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-7454HIGH7.8
  • Autodesk 3ds Max logoAutodesk 3ds Max
  • cpe:2.3:a:autodesk:3ds_max
NoYesMay 26, 2026
CVE-2026-7452HIGH7.8
  • Autodesk 3ds Max logoAutodesk 3ds Max
  • cpe:2.3:a:autodesk:3ds_max
NoYesMay 26, 2026
CVE-2026-7451HIGH7.8
  • Autodesk 3ds Max logoAutodesk 3ds Max
  • cpe:2.3:a:autodesk:3ds_max
NoYesMay 26, 2026
CVE-2026-7453MEDIUM5.5
  • Autodesk 3ds Max logoAutodesk 3ds Max
  • cpe:2.3:a:autodesk:3ds_max
NoYesMay 26, 2026
CVE-2026-7450MEDIUM5.5
  • Autodesk 3ds Max logoAutodesk 3ds Max
  • cpe:2.3:a:autodesk:3ds_max
NoYesMay 26, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management