← Vulnerability feed

Vulnerability record · CVE-2023-25002 · published 27 June 2023

CVE-2023-25002: Autodesk 3ds max use after free vulnerability

Autodesk · 3ds Max

A maliciously crafted SKP file in Autodesk products is used to trigger use-after-free vulnerability. Exploitation of this vulnerability may lead to code execution.

7.8 CVSS 3.1 High EPSS 0.35% · top 74.0% CWE-416 · Use after free
7.8CVSS 3.1 base score
0.35%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A maliciously crafted SKP file in Autodesk products is used to trigger use-after-free vulnerability. Exploitation of this vulnerability may lead to code execution.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-25002 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2014-2967Autodesk vred os command injection vulnerabilityAutodesk VRED Professional 2014 before SR1 SP8 allows remote attackers to execute arbitrary code via Python os library calls in Python API commands t…EPSS 5.1%9.3CVE-2009-3577Autodesk 3ds max code injection vulnerabilityAutodesk 3D Studio Max (3DSMax) 6 through 9 and 2008 through 2010 allows remote attackers to execute arbitrary code via a .max file with a MAXScript …EPSS 5.1%8.4CVE-2026-0537Autodesk 3ds max out-of-bounds write vulnerabilityA maliciously crafted RGB file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage thi…EPSS 0.18%8.4CVE-2026-0538Autodesk 3ds max out-of-bounds write vulnerabilityA maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor can leverage …EPSS 0.18%8.4CVE-2026-0660Autodesk 3ds max stack-based buffer overflow vulnerabilityA maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can cause a Stack-Based Buffer Overflow vulnerability. A malicious actor can le…EPSS 0.20%8.4CVE-2026-0661Autodesk 3ds max out-of-bounds write vulnerabilityA maliciously crafted RGB file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage thi…EPSS 0.18%7.8CVE-2026-7455Autodesk 3ds max out-of-bounds write vulnerabilityA maliciously crafted FLT file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage …EPSS 0.19%7.8CVE-2026-16783Autodesk 3ds max out-of-bounds write vulnerabilityA maliciously crafted ABC file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage …EPSS 0.13%

Source: NIST National Vulnerability Database (record CVE-2023-25002), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.