Impact
Substance3D – Sampler is affected by a heap‑based buffer overflow that allows an attacker to execute arbitrary code within the victim’s user context. The flaw is triggered when the application processes an unsanitized input file, which can overwrite the heap and allow code execution. The underlying weakness is a classic heap overflow (CWE‑122).
Affected Systems
The vulnerability affects Adobe Substance 3D Sampler. No specific version ranges are provided, so any installation of the application remains potentially vulnerable until a fix is applied.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity. The EPSS score is not available, and the issue is not listed in CISA’s KEV catalog, implying no publicly known exploitation yet. Exploitation requires user interaction: a victim must open a malicious file. Consequently, the risk is limited to scenarios where a user loads an attacker‑crafted document, but the potential for arbitrary code execution makes it a serious threat if such a file is used.
OpenCVE Enrichment