Impact
Substance3D – Designer is affected by a heap‑based buffer overflow that can lead to arbitrary code execution in the context of the user. The vulnerability is a classic stack corruption flaw (CWE‑122). Exploitation requires the victim to open a crafted file, after which the attacker can run code with the same privileges as the user.
Affected Systems
Adobe Substance 3D Designer, but specific affected version information is not provided in the advisory.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity. No EPSS score is available, and the flaw is not listed in the CISA KEV catalog, suggesting limited or no public exploitation at this time. Because user interaction is required, the risk can be mitigated by avoiding malicious files and applying vendor updates.
OpenCVE Enrichment