Impact
The vulnerability is a heap-based buffer overflow in Adobe Substance 3D Sampler that can lead to arbitrary code execution in the context of the current user. This flaw, identified as CWE-122, occurs when the application processes an oversized or malformed file, allowing an attacker to overwrite memory and hijack control flow. An attacker who successfully overflows the buffer could execute arbitrary code, potentially gaining full control over the victim’s system.
Affected Systems
Adobe Substance 3D Sampler is the affected product. No specific version data is provided in the CVE entry, so all releases of this software are potentially vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity impact. Because exploitation requires the victim to open a malicious file, the attack vector is user‑interaction, which limits remote exploitation. EPSS data is not available, but the CVE is not listed in CISA’s KEV catalog, suggesting that widespread exploitation has not yet been observed. Nonetheless, the high severity and potential for arbitrary code execution warrant prompt remediation.
OpenCVE Enrichment