CVE-2026-7454
Autodesk 3ds Max vulnerability analysis and mitigation

Overview

CVE-2026-7454 is a memory corruption vulnerability in Autodesk 3ds Max triggered by parsing a maliciously crafted WRL (VRML World) file, enabling arbitrary code execution in the context of the current process. It affects Autodesk 3ds Max versions 2026 (prior to 2026.1) and 2027 (prior to 2027.1). The vulnerability was published on May 26, 2026, with patches made available the same day. It carries a CVSS v3.1 base score of 7.8 (High) (Autodesk Advisory, GitHub Advisory).

Technical details

The root cause is classified as CWE-120 (Buffer Copy without Checking Size of Input / Classic Buffer Overflow): the WRL file parser in 3ds Max copies input data into a buffer without validating that the input size does not exceed the destination buffer's capacity, resulting in memory corruption. The attack vector is local, requiring no privileges but requiring user interaction — specifically, a victim must open a maliciously crafted WRL file. Exploitation triggers an out-of-bounds write condition (also estimated as CWE-787) that can corrupt process memory in a manner sufficient to redirect code execution (GitHub Advisory, Autodesk Advisory).

Impact

Successful exploitation allows an attacker to execute arbitrary code with the privileges of the Autodesk 3ds Max process on the victim's system, resulting in high confidentiality, integrity, and availability impact. An attacker who achieves code execution in this context could access sensitive project files, install malware, or pivot to other resources accessible by the user account running 3ds Max. The scope is limited to the affected process and user context, with no scope change, but full compromise of the local user session is possible (Autodesk Advisory, GitHub Advisory).

Exploitation steps

  1. Craft malicious WRL file: Create a specially crafted VRML/WRL file containing oversized or malformed field data designed to overflow the destination buffer in 3ds Max's WRL parser, potentially overwriting adjacent memory including return addresses or function pointers.
  2. Deliver the file to the target: Use social engineering, phishing, or supply-chain methods to deliver the malicious WRL file to a user who has Autodesk 3ds Max 2026 or 2027 (unpatched) installed — for example, disguising it as a legitimate 3D model asset.
  3. Induce user interaction: Convince the victim to open the WRL file in 3ds Max (e.g., via double-click, drag-and-drop, or file import), triggering the vulnerable parsing code path.
  4. Trigger memory corruption: The parser copies the oversized input into a fixed-size buffer without bounds checking, corrupting adjacent memory and potentially overwriting control-flow data.
  5. Achieve code execution: With appropriate payload crafting (e.g., ROP chain or shellcode), the attacker redirects execution to their payload, running arbitrary code with the privileges of the 3ds Max process and the logged-in user (Autodesk Advisory, GitHub Advisory).

Indicators of compromise

  • File System: Unexpected WRL files in user download directories, temp folders, or shared project repositories; presence of unknown executables or scripts created shortly after a WRL file was opened by 3ds Max.
  • Process: Unusual child processes spawned by the 3ds Max process (e.g., cmd.exe, powershell.exe, curl, mshta.exe); 3ds Max process crashing or exhibiting abnormal CPU/memory usage upon opening a WRL file.
  • Logs: Application crash logs or Windows Event Log entries (Event ID 1000/1001) referencing 3dsmax.exe with faulting module related to WRL/VRML parsing; unexpected process creation events (Event ID 4688) with 3dsmax.exe as parent process.
  • Network: Outbound network connections initiated by 3dsmax.exe to unknown external IP addresses or domains, particularly shortly after opening a WRL file.

Mitigation and workarounds

Autodesk has released patched versions: 3ds Max 2026.1 and 3ds Max 2027.1, which address this vulnerability. Users should update immediately via Autodesk Access or the Autodesk desktop app. As a workaround, avoid opening WRL files from untrusted or unverified sources, and consider restricting WRL file type associations or implementing file validation controls in environments where 3ds Max is deployed (Autodesk Advisory, GitHub Advisory).

Community reactions

The vulnerability received routine coverage from vulnerability tracking platforms including VulnDB, CVEFeed, and Vulners shortly after disclosure. A brief mention appeared on Mastodon via The Hacker Wire account. No significant researcher commentary, vendor blog posts, or major media coverage has been identified beyond standard vulnerability database entries and the CISA weekly bulletin inclusion (CISA Bulletin).

Additional resources


SourceThis report was generated using AI

Related Autodesk 3ds Max vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-7454HIGH7.8
  • Autodesk 3ds Max logoAutodesk 3ds Max
  • cpe:2.3:a:autodesk:3ds_max
NoYesMay 26, 2026
CVE-2026-7452HIGH7.8
  • Autodesk 3ds Max logoAutodesk 3ds Max
  • cpe:2.3:a:autodesk:3ds_max
NoYesMay 26, 2026
CVE-2026-7451HIGH7.8
  • Autodesk 3ds Max logoAutodesk 3ds Max
  • cpe:2.3:a:autodesk:3ds_max
NoYesMay 26, 2026
CVE-2026-7453MEDIUM5.5
  • Autodesk 3ds Max logoAutodesk 3ds Max
  • cpe:2.3:a:autodesk:3ds_max
NoYesMay 26, 2026
CVE-2026-7450MEDIUM5.5
  • Autodesk 3ds Max logoAutodesk 3ds Max
  • cpe:2.3:a:autodesk:3ds_max
NoYesMay 26, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management