CVE-2026-7455
Analyzed Analyzed - Analysis Complete

Out-of-Bounds Write in Autodesk 3ds Max via FLT File

Vulnerability report for CVE-2026-7455, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-24

Last updated on: 2026-08-28

Assigner: Autodesk

Description

A maliciously crafted FLT file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-24
Last Modified
2026-08-28
Generated
2026-09-14
AI Q&A
2026-08-25
EPSS Evaluated
2026-09-12
NVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
autodesk 3ds_max From 2026 (inc) to 2026.3.4 (exc)
autodesk 3ds_max From 2027 (inc) to 2027.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-787 The product writes data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves a maliciously crafted FLT file that, when processed by Autodesk 3ds Max, triggers an Out-of-Bounds Write issue. This flaw could allow an attacker to crash the application, corrupt data, or execute arbitrary code within the current process.

Detection Guidance

Detection of this vulnerability requires monitoring Autodesk 3ds Max for crashes or unusual behavior when processing FLT files. Check for application logs for segmentation faults or memory access violations. Ensure 3ds Max is updated to the latest version to mitigate risks.

Impact Analysis

If exploited, this vulnerability could lead to application crashes, data corruption, or unauthorized code execution on your system. This might compromise sensitive files or allow attackers to take control of your system if they trick you into opening a malicious FLT file.

Compliance Impact

This vulnerability could potentially lead to unauthorized code execution or data corruption, which may result in unauthorized access to sensitive data. This could impact compliance with GDPR by risking data breaches or HIPAA by compromising protected health information if exploited.

Mitigation Strategies

Update Autodesk 3ds Max to the latest version provided by Autodesk to patch the vulnerability. Avoid opening untrusted FLT files and restrict access to 3ds Max to trusted users only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-7455. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart