Impact
The vulnerability in Adobe Substance 3D Sampler is a heap‑based buffer overflow that allows code execution in the context of the currently logged‑in user. Exploitation requires the victim to open a maliciously crafted file, after which arbitrary code can run with the user’s privileges.
Affected Systems
Adobe Substance 3D Sampler is the affected product. Version information is not disclosed in the advisory, so all installations are potentially vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Because the exploit needs the user to manually open a file, the attack vector is mainly interactive; the likelihood of widespread exploitation is lower than a purely remote flaw, but the impact remains significant if a malicious file is delivered to an end‑user.
OpenCVE Enrichment