Impact
The vulnerability is a heap-based buffer overflow in Adobe Substance 3D Sampler that can allow an attacker to execute arbitrary code in the context of the user who opens a malicious file. The impact is that the attacker could gain full control over the application and potentially the underlying system, accessing or modifying data as the user. The weakness is a classic buffer overflow, identified as CWE‑122.
Affected Systems
Adobe Substance 3D Sampler versions 5.1.3 and all earlier releases are affected. Users running any of those versions are vulnerable until they update to a patched release.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity. Exploitation requires user interaction—an attacker must persuade a user to open a crafted file. EPSS data is unavailable and the vulnerability is not listed in the CISA KEV catalog, so while widespread exploitation has not been reported, the potential for arbitrary code execution in a user’s context remains a significant concern and warrants prompt remediation.
OpenCVE Enrichment