Impact
An out‑of‑bounds write in Adobe Substance3D Modeler 1.22.4 and earlier permits arbitrary code execution when a user opens a specially crafted file.
Affected Systems
Adobe Substance3D Modeler versions 1.22.4 and any earlier releases.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.8, indicating high severity, while the EPSS score is under 1%, implying a low current likelihood of exploitation. It is not listed in the CISA KEV catalog, so no confirmed active attacks are known. The flaw requires user interaction – an attacker must supply a malicious file that the user opens – so it is a local or user‑mediated attack vector. When executed, the code runs in the context of the current user.
OpenCVE Enrichment