A maliciously crafted project directory, when opening a max file in Autodesk 3ds Max, could lead to execution of arbitrary code in the context of the current process due to an Untrusted Search Path being utilized.
Metrics
Affected Vendors & Products
References
History
Fri, 06 Feb 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:autodesk:3ds_max:*:*:*:*:*:*:*:* |
Wed, 04 Feb 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 04 Feb 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A maliciously crafted project directory, when opening a max file in Autodesk 3ds Max, could lead to execution of arbitrary code in the context of the current process due to an Untrusted Search Path being utilized. | |
| Title | Untrusted Search Path Vulnerability when opening max Files | |
| First Time appeared |
Autodesk
Autodesk 3ds Max |
|
| Weaknesses | CWE-426 | |
| CPEs | cpe:2.3:a:autodesk:3ds_max:2026:*:*:*:*:*:*:* | |
| Vendors & Products |
Autodesk
Autodesk 3ds Max |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: autodesk
Published:
Updated: 2026-02-06T04:55:24.319Z
Reserved: 2026-01-06T19:58:25.162Z
Link: CVE-2026-0662
Updated: 2026-02-04T16:50:37.226Z
Status : Analyzed
Published: 2026-02-04T17:16:13.100
Modified: 2026-02-06T14:45:33.330
Link: CVE-2026-0662
No data.