Impact
Substance3D – Modeler versions 1.22.5 and earlier contain an out‑of‑bounds read flaw (CWE‑125) that allows a malicious file to leak data stored in memory. The vulnerability can reveal confidential or proprietary information if the reader exploits the exposed memory regions. This is an information disclosure flaw, not a code execution issue, and requires attacker control over a file that a user opens.
Affected Systems
The affected product is Adobe Corporation’s Substance3D – Modeler. Versions 1.22.5 and earlier are impacted. No other vendors are listed.
Risk and Exploitability
The CVSS base score is 5.5, reflecting a moderate severity for confidentiality impact. The EPSS score is less than 1%, indicating a low but non‑zero exploitation probability, and the flaw is not in the CISA KEV catalog. Exploitation requires the victim to open a specially crafted file, so the attack vector is local user interaction; an attacker must coerce or deceive a user into running the file within Substance3D – Modeler.
OpenCVE Enrichment