
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-7453 is a Stack Exhaustion (Uncontrolled Recursion) vulnerability in Autodesk 3ds Max that can be triggered by parsing a maliciously crafted WRL (VRML World) file, leading to a denial-of-service condition. It affects Autodesk 3ds Max versions 2026 (prior to 2026.1) and 2027 (prior to 2027.1). The vulnerability was published on May 26, 2026, with patches made available the same day. It carries a CVSS v3.1 base score of 5.5 (Medium) per NVD, or 5.3 (Moderate) per the GitHub Advisory (GitHub Advisory, Autodesk Advisory).
The root cause is CWE-674 (Uncontrolled Recursion): Autodesk 3ds Max does not properly control the depth of recursion when parsing WRL (VRML) files, allowing a specially crafted file to exhaust the program stack. The attack vector is local — an attacker must supply a malicious WRL file that a user then opens in 3ds Max (user interaction required), with no privileges required on the attacker's part. The uncontrolled recursion consumes the call stack until the application crashes, consistent with CAPEC-230 (Serialized Data with Nested Payloads) and CAPEC-231 (Oversized Serialized Data Payloads) attack patterns (GitHub Advisory, Autodesk Advisory).
Successful exploitation causes Autodesk 3ds Max to crash, rendering the application unavailable and resulting in a denial-of-service condition. There is no impact on confidentiality or integrity per the primary NVD CVSS scoring (C:N/I:N/A:H), meaning attackers cannot access or modify data through this vulnerability. The impact is limited to the local workstation running the affected 3ds Max version; no lateral movement or data exfiltration risk has been identified (GitHub Advisory, Autodesk Advisory).
.wrl files in user download folders, temp directories, or shared drives; files with unusual nesting depth or abnormally large recursive structures when inspected.3dsmax.exe or related processes; crash dump files (.dmp) generated in the 3ds Max installation or user profile directory.3dsmax.exe process without user-initiated close action; stack overflow exceptions visible in crash reports or Windows Error Reporting logs.Autodesk has released patched versions: 3ds Max 2026.1 and 3ds Max 2027.1. Users should update to these versions immediately via the Autodesk Access portal. As interim workarounds, organizations should implement file validation controls, restrict import of WRL files from untrusted sources, and train users to avoid opening WRL files received from unknown parties (Autodesk Advisory, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."