Impact
Substance3D – Sampler contains a heap‑based buffer overflow that allows an attacker to execute arbitrary code in the context of the user interacting with the application. The flaw is triggered when a specially crafted file is opened. Successful exploitation would give the attacker the same privileges as the current user.
Affected Systems
The affected product is Adobe Substance 3D Sampler. Version information is not disclosed in the advisory.
Risk and Exploitability
The vulnerability scores a CVSS of 7.8, indicating a high severity. It does not appear in the CISA KEV list and no EPSS value is published, so the exact exploitation likelihood is unknown. However, because the attack requires only a malicious file to be opened by a user, the vector is a user‑initiated file opening, making the problem broadly relevant for any user of the application.
OpenCVE Enrichment