A maliciously crafted DWG file, when parsed through Autodesk 3ds Max, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
Attack Parameters
Impact Assessment
CVSS Vector v3.1
Weakness Type (CWE)
Vulnerable Products 1
Known Affected Software Configurations 1
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Autodesk 3ds_Max
cpe:2.3:a:autodesk:3ds_max:*:*:*:*:*:*:*:*
|
2026
|
2026.3
|