Impact
Substance3D Designer versions 15.1.0 and earlier contain an out‑of‑bounds read that can expose data stored in memory. The flaw arises when the software reads beyond the bounds of a buffer, potentially leaking sensitive information. The issue is classified as CWE‑125.
Affected Systems
Adobe Substanеt3D Designer 15.1.0 and any earlier release are affected.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate severity. The EPSS score of less than 1% shows a very low probability of exploitation. The vulnerability is not recorded in CISA’s KEV catalog. The flaw requires user interaction; a victim must open a malicious file for the read to occur, which limits the attacker’s reach to scenarios where a user can be lured to process a file.
OpenCVE Enrichment