Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-23874 | A maliciously crafted PSD file, when linked or imported into Autodesk 3ds Max, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process. |
Tue, 19 Aug 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Autodesk 3ds Max
|
|
| CPEs | cpe:2.3:a:autodesk:3ds_Max:2026.2:*:*:*:*:*:*:* | |
| Vendors & Products |
Autodesk 3ds Max
|
|
| References |
|
Wed, 13 Aug 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:autodesk:3ds_max:*:*:*:*:*:*:*:* |
Thu, 07 Aug 2025 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Autodesk
Autodesk 3ds Max |
|
| Vendors & Products |
Autodesk
Autodesk 3ds Max |
Wed, 06 Aug 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 06 Aug 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A maliciously crafted PSD file, when linked or imported into Autodesk 3ds Max, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process. | |
| Title | PSD File Parsing Out-of-Bounds Read Vulnerability | |
| Weaknesses | CWE-125 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: autodesk
Published:
Updated: 2025-08-19T13:21:17.924Z
Reserved: 2025-06-25T13:44:04.484Z
Link: CVE-2025-6632
Updated: 2025-08-06T20:52:05.496Z
Status : Analyzed
Published: 2025-08-06T21:15:31.920
Modified: 2025-11-13T19:41:50.260
Link: CVE-2025-6632
No data.
OpenCVE Enrichment
Updated: 2025-08-07T07:08:24Z
EUVD