Impact
Substance3D - Sampler is affected by an out‑of‑bounds write. The flaw allows a malicious document to overwrite memory and can lead to arbitrary code execution in the context of the user who opens the file. The vulnerability is a classic buffer overrun (CWE‑787) where uncontrolled data is written past a boundary, which can corrupt instruction pointers, flags or other critical structures used by the application.
Affected Systems
Adobe Substance 3D Sampler, all versions are potentially impacted because the CVE description does not specify any fixed releases or version ranges.
Risk and Exploitability
The CVSS score of 7.8 indicates a high impact if the flaw is triggered. Exploitation requires the victim to open a crafted file, so it is a user‑interaction risk. The EPSS score is unavailable, but the lack of listing in the CISA KEV catalog suggests no confirmed exploitation at this time. Nevertheless, the combination of high severity and user‑triggered activation warrants immediate attention.
OpenCVE Enrichment