Impact
Substance3D - Sampler versions 5.1.0 and earlier contain an out‑of‑bounds write (CWE‑787) that can be triggered by a crafted file, allowing an attacker to execute arbitrary code in the context of the current user. This vulnerability directly threatens confidentiality, integrity, and availability by permitting unauthorized code execution, which could lead to data exposure, tampering, or system disruption.
Affected Systems
Adobe’s Substance3D - Sampler is affected. All installations running version 5.1.0 or earlier are vulnerable; newer releases contain the patch for this issue.
Risk and Exploitability
The CVSS base score of 7.8 indicates a high security impact, but the EPSS probability is less than 1 %, suggesting a low likelihood of widespread exploitation. The vulnerability is not listed in the KEV catalog, and its exploitation path requires a local, user‑initiated action—specifically the opening of a malicious Substance3D sampler file—rather than a remote trigger.
OpenCVE Enrichment