Impact
The vulnerability is a NULL pointer dereference that causes Substance 3D Designer to crash, resulting in a denial‑of‑service condition. An attacker can invoke the crash by providing a specially crafted file that the application processes.
Affected Systems
Adobe Substance 3D Designer is affected. No specific version range is listed in the advisory, so all installations of the product are potentially vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate severity exploit. The EPSS score is not available and the issue is not listed in CISA KEV, suggesting the likelihood of widespread exploitation is low. The attack vector requires the victim to open a malicious file, so exploitation depends on user interaction. Once triggered, the application will stop responding, leading to a local denial of service.
OpenCVE Enrichment