← Vulnerability feed

Vulnerability record · CVE-2009-3577 · published 24 November 2009

CVE-2009-3577: Autodesk 3ds max code injection vulnerability

Autodesk · 3ds Max

Autodesk 3D Studio Max (3DSMax) 6 through 9 and 2008 through 2010 allows remote attackers to execute arbitrary code via a .max file with a MAXScript statement that calls the DOSCommand method, related to "application callbacks."

9.3 CVSS 2.0 High EPSS 5.1% · top 7.9% CWE-94 · Code injection
9.3CVSS 2.0 base score
5.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

Autodesk 3D Studio Max (3DSMax) 6 through 9 and 2008 through 2010 allows remote attackers to execute arbitrary code via a .max file with a MAXScript statement that calls the DOSCommand method, related to "application callbacks."

AV:N/AC:M/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2009-3577 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.4CVE-2026-0537Autodesk 3ds max out-of-bounds write vulnerabilityA maliciously crafted RGB file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage thi…EPSS 0.18%8.4CVE-2026-0538Autodesk 3ds max out-of-bounds write vulnerabilityA maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor can leverage …EPSS 0.18%8.4CVE-2026-0660Autodesk 3ds max stack-based buffer overflow vulnerabilityA maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can cause a Stack-Based Buffer Overflow vulnerability. A malicious actor can le…EPSS 0.20%8.4CVE-2026-0661Autodesk 3ds max out-of-bounds write vulnerabilityA maliciously crafted RGB file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage thi…EPSS 0.18%7.8CVE-2026-7455Autodesk 3ds max out-of-bounds write vulnerabilityA maliciously crafted FLT file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage …EPSS 0.19%7.8CVE-2026-16783Autodesk 3ds max out-of-bounds write vulnerabilityA maliciously crafted ABC file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage …EPSS 0.13%7.8CVE-2026-19568Autodesk 3ds max classic buffer overflow vulnerabilityA maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage thi…EPSS 0.13%7.8CVE-2026-16782Autodesk 3ds max out-of-bounds read vulnerabilityA maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage t…EPSS 0.21%

Source: NIST National Vulnerability Database (record CVE-2009-3577), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.