Home
HIGH: 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HDefault status
unaffected
7.4.4.1 (custom) before 7.4.4.2
affected
Default status
unaffected
7.4.4.1 (custom) before 7.4.4.2
affected
Default status
unaffected
2026.2 (custom) before 2026.3.2
affected
Description
A maliciously crafted USD file, when loaded or imported into Autodesk Arnold or Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
Problem types
Product status
7.4.4.1 (custom) before 7.4.4.2
7.4.4.1 (custom) before 7.4.4.2
2026.2 (custom) before 2026.3.2
References
www.autodesk.com/products/autodesk-access/overview
github.com/Autodesk/arnold-usd
www.autodesk.com/trust/security-advisories/adsk-sa-2026-0003