Description
A Stack-based Buffer Overflow Vulnerability in Autodesk 3ds Max 2022, 2021, and 2020 may lead to code execution through the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer when parsing ActionScript Byte Code files. This vulnerability may allow arbitrary code execution on affected installations of Autodesk 3ds Max.
Scores
CVSS v3
7.8
EPSS
0.0006
EPSS Percentile
19.1%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Details
CWE
CWE-1284
Status
published
Products (1)
autodesk/3ds_max
2020 - 2020.3.6
Published
Aug 10, 2022
Tracked Since
Feb 18, 2026