Impact
Substance 3D Sampler contains an out‑of‑bounds write flaw that can be triggered by loading a specially crafted file. This bug allows an attacker to corrupt memory adjacent to the intended buffer, enabling the execution of attacker‑supplied code in the context of the current user. The vulnerability is a classic example of a buffer overwrite (CWE‑787).
Affected Systems
The Adobe Substance 3D Sampler application is the affected product. No specific version numbers are listed in the advisory, so all installations of the product prior to the published patch are potentially vulnerable.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity impact. Because exploitation requires a victim to open a malicious file, the attack vector is user interaction (local). The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known mass exploitation at this time. Nonetheless, the ability to achieve arbitrary execution can have catastrophic consequences, so the risk warrants immediate remediation.
OpenCVE Enrichment