Impact
Substance3D Sampler contains an out‑of‑bounds write flaw that permits a malicious file to corrupt memory, allowing the execution of arbitrary code within the privileges of the user who opens the file.
Affected Systems
Adobe Substance 3D Sampler is the affected product; specific product versions were not disclosed in the advisory.
Risk and Exploitability
The CVSS score of 7.8 marks the issue as high severity, and the vulnerability requires user interaction; a victim must deliberately open a crafted file. EPSS is not available, so the probability of exploitation cannot be quantified, and the flaw is not listed in the CISA KEV catalog. The current attacker model is local, relying on a compromised user to trigger the exploit, but the outcome is devastating in that it results in arbitrary code execution.
OpenCVE Enrichment