← Vulnerability feed

Vulnerability record · CVE-2022-25793 · published 10 August 2022

CVE-2022-25793: Autodesk 3ds max vulnerability

Autodesk · 3ds Max

A Stack-based Buffer Overflow Vulnerability in Autodesk 3ds Max 2022, 2021, and 2020 may lead to code execution through the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer when parsing ActionScript Byte Code files. This vulnerability may allow arbitrary code execution on affected installations of Autodesk 3ds Max.

7.8 CVSS 3.1 High EPSS 0.39% · top 69.5% CWE-1284 · CWE-1284
7.8CVSS 3.1 base score
0.39%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A Stack-based Buffer Overflow Vulnerability in Autodesk 3ds Max 2022, 2021, and 2020 may lead to code execution through the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer when parsing ActionScript Byte Code files. This vulnerability may allow arbitrary code execution on affected installations of Autodesk 3ds Max.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-25793 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2009-3577Autodesk 3ds max code injection vulnerabilityAutodesk 3D Studio Max (3DSMax) 6 through 9 and 2008 through 2010 allows remote attackers to execute arbitrary code via a .max file with a MAXScript …EPSS 5.1%8.4CVE-2026-0537Autodesk 3ds max out-of-bounds write vulnerabilityA maliciously crafted RGB file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage thi…EPSS 0.19%8.4CVE-2026-0661Autodesk 3ds max out-of-bounds write vulnerabilityA maliciously crafted RGB file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage thi…EPSS 0.19%8.4CVE-2026-0538Autodesk 3ds max out-of-bounds write vulnerabilityA maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor can leverage …EPSS 0.19%8.4CVE-2026-0660Autodesk 3ds max stack-based buffer overflow vulnerabilityA maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can cause a Stack-Based Buffer Overflow vulnerability. A malicious actor can le…EPSS 0.22%7.8CVE-2026-7455Autodesk 3ds max out-of-bounds write vulnerabilityA maliciously crafted FLT file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage …EPSS 0.19%7.8CVE-2026-16783Autodesk 3ds max out-of-bounds write vulnerabilityA maliciously crafted ABC file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage …EPSS 0.13%7.8CVE-2026-19568Autodesk 3ds max classic buffer overflow vulnerabilityA maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage thi…EPSS 0.13%

Source: NIST National Vulnerability Database (record CVE-2022-25793), CISA KEV, FIRST EPSS (scores of 2026-10-08). This page is refreshed as NVD updates the record.