CVE-2025-11797: DWG File Parsing Use-After-Free Vulnerability
A maliciously crafted DWG file, when parsed through Autodesk 3ds Max, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11797?
CVE-2025-11797 is classified as a high-severity vulnerability due to its potential to cause crashes and execute arbitrary code.
How do I fix CVE-2025-11797?
To address CVE-2025-11797, ensure that you are using the latest version of Autodesk 3ds Max, as updates may contain mitigations for this vulnerability.
What exploitation methods are possible with CVE-2025-11797?
An attacker can exploit CVE-2025-11797 by crafting a malicious DWG file that, when opened in Autodesk 3ds Max, triggers the Use-After-Free vulnerability.
What are the potential impacts of CVE-2025-11797?
The impacts of CVE-2025-11797 include application crashes, unauthorized access to sensitive data, and the execution of arbitrary code.
Which versions of Autodesk 3ds Max are affected by CVE-2025-11797?
CVE-2025-11797 affects all versions of Autodesk 3ds Max that process DWG files without appropriate security measures.