CVE-2026-7455: FLT File Parsing Out-of-Bounds Write Vulnerability in Autodesk 3ds Max
A maliciously crafted FLT file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
Affected Software
Event History
Frequently Asked Questions
What must an attacker do to exploit this vulnerability?
An attacker must provide a maliciously crafted FLT file and persuade a user to have Autodesk 3ds Max parse it. User interaction is required, and the vulnerable parsing occurs in the context of the current process.
What impact could successful exploitation have?
Successful exploitation may crash 3ds Max, corrupt data, or allow arbitrary code execution in the context of the current process. The reported severity is high, with impacts to confidentiality, integrity, and availability.
Is this exploitable remotely without user interaction?
The supplied vector is local and user interaction is required. The available information does not indicate unauthenticated remote exploitation without a user parsing a malicious FLT file.