VYPR
Medium severity6.6NVD Advisory· Published Jun 11, 2025· Updated Jun 17, 2026

CVE-2025-4605

CVE-2025-4605

Description

A maliciously crafted .usdc file, when loaded through Autodesk Maya, can force an uncontrolled memory allocation vulnerability. A malicious actor may leverage this vulnerability to cause a denial-of-service (DoS), or cause data corruption.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

7
  • Autodesk/Maya3 versions
    cpe:2.3:a:autodesk:maya:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:autodesk:maya:*:*:*:*:*:*:*:*range: >=2025,<2025.3.1
    • cpe:2.3:a:autodesk:maya:2025:*:*:*:*:*:*:*range: 2025
    • (no CPE)
  • cpe:2.3:a:autodesk:universal_scene_description:0.10:*:*:*:*:3ds_max:*:*+ 1 more
    • cpe:2.3:a:autodesk:universal_scene_description:0.10:*:*:*:*:3ds_max:*:*
    • cpe:2.3:a:autodesk:universal_scene_description:0.31.0:*:*:*:*:maya:*:*
  • cpe:2.3:a:autodesk:usd_for_3ds_max:max_usd_0.10:*:*:*:*:*:*:*
    Range: Max USD 0.10
  • Autodesk/Maya Usdcpe-rescue
    cpe:2.3:a:autodesk:usd_for_maya:maya_usd_0.31.0:*:*:*:*:*:*:*
    Range: Maya USD 0.31.0

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.