Impact
An out‑of‑bounds write vulnerability in Adobe Substance 3D Designer allows an attacker to overwrite memory beyond a buffer’s limits. This flaw can be exploited to execute arbitrary code in the context of the user who opens a malicious file. The vulnerability is identified as CWE‑787 and the official description notes that exploitation requires user interaction by opening a specially crafted file.
Affected Systems
Adobe Substance 3D Designer from Adobe is the affected product. No specific version ranges are listed in the provided data, so any installer or packaged product that includes the vulnerable code is potentially impacted until an update is applied.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.8, which reflects high impact and moderate to high exploitability. EPSS data is unavailable, and the issue is not listed in the CISA KEV catalog. Exploitation requires that the victim be deceived into opening a malicious file, indicating a user‑interaction vector. Overall risk is substantial for users who open unknown files, especially if the latest patches have not been applied.
OpenCVE Enrichment