Impact
A recent vulnerability in Adobe Substance 3D Designer allows an out‑of‑bounds write that can lead to arbitrary code execution when a user opens a malicious design file. The flaw is an unchecked write outside the bounds of a buffer, granting an attacker the ability to execute code with the privileges of the current user. This type of weakness is classified as CWE‑787 and can compromise system confidentiality, integrity, and availability if exploited.
Affected Systems
Adobe's Substance 3D Designer is the affected product. The advisory does not list specific version ranges, so any installed instance should be examined for updates at the vendor's site.
Risk and Exploitability
The vulnerability has a CVSS score of 7.8, indicating a high severity. EPSS data is not available, but the attack requires user interaction—specifically, opening a crafted file. The issue is not listed in CISA's KEV catalog, suggesting no widespread exploitation has been documented. Nonetheless, the high score and the potential for arbitrary code execution warrant immediate attention.
OpenCVE Enrichment