CVE-2026-7453
Autodesk 3ds Max vulnerability analysis and mitigation

Overview

CVE-2026-7453 is a Stack Exhaustion (Uncontrolled Recursion) vulnerability in Autodesk 3ds Max that can be triggered by parsing a maliciously crafted WRL (VRML World) file, leading to a denial-of-service condition. It affects Autodesk 3ds Max versions 2026 (prior to 2026.1) and 2027 (prior to 2027.1). The vulnerability was published on May 26, 2026, with patches made available the same day. It carries a CVSS v3.1 base score of 5.5 (Medium) per NVD, or 5.3 (Moderate) per the GitHub Advisory (GitHub Advisory, Autodesk Advisory).

Technical details

The root cause is CWE-674 (Uncontrolled Recursion): Autodesk 3ds Max does not properly control the depth of recursion when parsing WRL (VRML) files, allowing a specially crafted file to exhaust the program stack. The attack vector is local — an attacker must supply a malicious WRL file that a user then opens in 3ds Max (user interaction required), with no privileges required on the attacker's part. The uncontrolled recursion consumes the call stack until the application crashes, consistent with CAPEC-230 (Serialized Data with Nested Payloads) and CAPEC-231 (Oversized Serialized Data Payloads) attack patterns (GitHub Advisory, Autodesk Advisory).

Impact

Successful exploitation causes Autodesk 3ds Max to crash, rendering the application unavailable and resulting in a denial-of-service condition. There is no impact on confidentiality or integrity per the primary NVD CVSS scoring (C:N/I:N/A:H), meaning attackers cannot access or modify data through this vulnerability. The impact is limited to the local workstation running the affected 3ds Max version; no lateral movement or data exfiltration risk has been identified (GitHub Advisory, Autodesk Advisory).

Exploitation steps

  1. Craft malicious WRL file: Create a VRML/WRL file containing deeply nested or self-referential structures designed to trigger unbounded recursion in 3ds Max's WRL parser.
  2. Deliver the file: Distribute the malicious WRL file to a target user via email attachment, shared network drive, or social engineering (e.g., posing as a 3D asset).
  3. User opens the file: The target user opens the crafted WRL file in Autodesk 3ds Max 2026 or 2027 (prior to patched versions).
  4. Stack exhaustion triggered: The WRL parser recursively processes the nested structures without depth limits, exhausting the call stack.
  5. Application crash: 3ds Max crashes with a stack overflow exception, causing a denial-of-service condition on the affected workstation (GitHub Advisory, Autodesk Advisory).

Indicators of compromise

  • File System: Presence of unexpected or unsolicited .wrl files in user download folders, temp directories, or shared drives; files with unusual nesting depth or abnormally large recursive structures when inspected.
  • Logs: Windows Event Log entries showing application crash events (Event ID 1000) for 3dsmax.exe or related processes; crash dump files (.dmp) generated in the 3ds Max installation or user profile directory.
  • Process: Sudden termination of the 3dsmax.exe process without user-initiated close action; stack overflow exceptions visible in crash reports or Windows Error Reporting logs.

Mitigation and workarounds

Autodesk has released patched versions: 3ds Max 2026.1 and 3ds Max 2027.1. Users should update to these versions immediately via the Autodesk Access portal. As interim workarounds, organizations should implement file validation controls, restrict import of WRL files from untrusted sources, and train users to avoid opening WRL files received from unknown parties (Autodesk Advisory, GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related Autodesk 3ds Max vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-7454HIGH7.8
  • Autodesk 3ds Max logoAutodesk 3ds Max
  • cpe:2.3:a:autodesk:3ds_max
NoYesMay 26, 2026
CVE-2026-7452HIGH7.8
  • Autodesk 3ds Max logoAutodesk 3ds Max
  • cpe:2.3:a:autodesk:3ds_max
NoYesMay 26, 2026
CVE-2026-7451HIGH7.8
  • Autodesk 3ds Max logoAutodesk 3ds Max
  • cpe:2.3:a:autodesk:3ds_max
NoYesMay 26, 2026
CVE-2026-7453MEDIUM5.5
  • Autodesk 3ds Max logoAutodesk 3ds Max
  • cpe:2.3:a:autodesk:3ds_max
NoYesMay 26, 2026
CVE-2026-7450MEDIUM5.5
  • Autodesk 3ds Max logoAutodesk 3ds Max
  • cpe:2.3:a:autodesk:3ds_max
NoYesMay 26, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management