• News
    • General
    • Software
    • Industry
    • Video Games
    • Tech
    • Hardware
  • Articles
    • General
    • Reviews
    • Interviews
  • Tutorials
    • By subject
    • By software
    • Training & Courses
  • Resources
  • Spotlight
    • Reels
    • Films
    • Film Trailers
    • Game Trailers and Art
    • Breakdowns
    • Making Ofs
    • Music Videos
    • CG Videos
    • Images
    • Spots
  • Contribute News
News Channels:
  • CG News
  • 3DS Max
  • Blender
  • After Effects
  • Modo

Software > 3DS Max | Software

Autodesk identifies MAXScript exploit “PhysXPluginMfx” in 3ds Max

Aug 27, 2020 by CGPress Staff
8 |
Tweet

Autodesk has identified and warned users of a MAXScript exploit in 3ds Max. “PhysXPluginMfx” is a variant of ALC2, ALC, CRP and ADLS that can corrupt 3ds Max software’s settings, run malicious code, and propagate to other MAX files if scene files containing the script are loaded into 3ds Max. A fix is already available and users are urged to install and run the free plugin available from the Autodesk App Store to detect and remove the malicious code.

Security Experts BitDefender also recently published a whitepaper about this exploit, suggesting that it was a “cyberespionage attack targeting an international architectural and video production company, pointing to an advanced threat actor and South Korean-based C&C infrastructure.” 

“During the investigation, Bitdefender researchers found that threat actors had an entire toolset featuring powerful spying capabilities and made use of a previously unknown vulnerability in a popular software widely used in 3D computer graphics (Autodesk 3ds Max) to compromise the target.”

For more detailed information about their investigation, pleased visit the Bitdefender website. 

Related News

  • 3DS Max 2014 SDK and Maxscript CHMs now available
  • Autodesk opens source code archive for Max SDK and MAXScript developers
  • 3DS Max 2012 Hotfix 1 available
8 Comments
Oldest
Newest
Inline Feedbacks
View all comments
Marcin
4 years ago

For any Max/Autodesk reps reading this: please inform all your customers immediately once you identify malware. You have all the contact info you need for this. I’m getting unrelated BS emails from Autodesk not even tangentially related to what I do, the Autodesk App informs me about every little update, but this is something I *really* want to learn about as soon as possible once you know it’s out there. You know, the majority of users do not actively scan the internet for CG related news, and wouldn’t it be for external sources many wouldn’t even know malware in Max is a thing.

Artur
Reply to  Marcin
4 years ago

Like they care about customers lol. 3DS Max has tons of background processes running, they should update one of them to track that malware and block it.

Martin
Reply to  Artur
4 years ago

We do care and we have had a team working on security for a while.

Artur
Reply to  Martin
4 years ago

This is actually great, both response and time.

Damm
Reply to  Martin
4 years ago

If you could have a team also working on making your software features good..

Dubtronics
4 years ago

What are the chances of such exploits spreading to other software? We are constantly downloading files from other users online for example from a forum that anyone can access.

Ehm
4 years ago

Does anyone have a copy of that .mse file mentioned in the BitDefender paper?

Jhon
4 years ago

Max= VIRUs

ADVERTISEMENT

Latest Comments

  • Guest (the original) on Thinkbox MX Plugin Suite for current 3ds Max versions now available
  • MauricioPC on Thinkbox MX Plugin Suite for current 3ds Max versions now available
  • G_L on Autodesk releases 3ds Max 2026
  • G_L on Autodesk releases 3ds Max 2026
  • Senorpablo on Autodesk releases 3ds Max 2026
  • Guest (the original) on Autodesk releases 3ds Max 2026
  • G_L on Autodesk releases 3ds Max 2026
  • G_L on Autodesk releases 3ds Max 2026

Latest Features

1

Review of the Huion Kamvas 13 Pen Display for 3D artists

6

Archvis artists – what the hell do they do?

See All CGPress Features

Follow CGPress

Terms and Conditions | Privacy Policy | Cookie Policy
Copyright ©2000-2025 CGPress. All rights reserved.

About Us | Contact Us | Contribute News | Advertise
facebook
twitter
rss
wpDiscuz
Manage Cookie Consent

CGPress uses technology like cookies to analyse the number of visitors to our site and how it is navigated. We DO NOT sell or profit from your data beyond displaying inconspicuous adverts relevant to CG artists. It'd really help us out if you could accept the cookies, but of course we appreciate your choice not to share data. 

Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
Manage options Manage services Manage {vendor_count} vendors Read more about these purposes
View preferences
{title} {title} {title}