CVE-2025-4605: Autodesk Maya

Medium severity, CVSS 6.6. EPSS: 0.2% chance of exploitation in the next 30 days.

A maliciously crafted .usdc file, when loaded through Autodesk Maya, can force an uncontrolled memory allocation vulnerability. A malicious actor may leverage this vulnerability to cause a denial-of-service (DoS), or cause data corruption.

Affected products

  • Autodesk Maya: from 2025, before 2025.3.1 (fixed in 2025.3.1)
  • Autodesk Universal Scene Description: version 0.10 only; version 0.31.0 only

Published 2025-06-11. Last modified 2026-06-17.