Impact
The vulnerability is an out‑of‑bounds write in Adobe Substance 3D Sampler that can be exploited to execute arbitrary code with the privileges of the current user. It arises from incorrect bounds checking when processing user supplied data, a weakness identified as CWE‑787. The attack can lead to full compromise of the affected system if the victim executes code without further isolation.
Affected Systems
Adobe offers Substance 3D Sampler as the affected product. No specific version numbers are provided in the advisory, indicating that all versions prior to the fix are potentially vulnerable.
Risk and Exploitability
The CVSS score of 7.8 signifies a high severity rating. The EPSS score is unavailable, but the vulnerability requires the victim to open a malicious file, so it is a user‑interaction exploit. Because it is not listed in the CISA KEV catalog, no current widespread exploitation is reported, yet the high severity and reliance on local file handling present a significant risk for environments that process untrusted 3D asset files.
OpenCVE Enrichment