Impact
Substance3D Designer contains a heap-based buffer overflow that enables an attacker to gain arbitrary code execution in the context of the user who opens a malicious file. The flaw is a classic CWE‑122 boundary error that can be triggered by malformed input data processed while the application is running.
Affected Systems
The vulnerability affects Adobe Substance 3D Designer. No specific product versions are listed in the advisory, so any deployment of the software is potentially at risk until patched.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity, but the EPSS score is not available. The issue is not in the CISA KEV catalog. Exploitation requires user interaction: a victim must open a malicious file, so the attack surface depends on social engineering or compromised content.
OpenCVE Enrichment