CVE-2023-25002: Autodesk 3ds Max

High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.

A maliciously crafted SKP file in Autodesk products is used to trigger use-after-free vulnerability. Exploitation of this vulnerability may lead to code execution.

Affected products

  • Autodesk 3ds Max: version 2022 only; version 2023 only
  • Autodesk Navisworks: version 2022 only; version 2023 only
  • Autodesk Revit: version 2022 only; version 2023 only
  • Autodesk Vred: version 2023 only

Published 2023-06-27. Last modified 2026-06-17.