Impact
A stack-based buffer overflow in Adobe Substance 3D Sampler allows an attacker to execute arbitrary code in the context of the current user. The flaw is triggered by processing a malicious file, leading to memory corruption and control‑flow hijacking.
Affected Systems
Adobe Substance 3D Sampler by Adobe. The advisory does not specify affected versions; any installation capable of opening files is potentially vulnerable.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, and the vulnerability requires user interaction—a victim must open a malicious file. EPSS data is unavailable, so attack likelihood is unclear, but the threat is not listed in CISA KEV. An attacker must craft a malicious file and convince a user to open it, making exploitation possible but not automatic.
OpenCVE Enrichment