Impact
Substance3D Designer contains a heap-based buffer overflow (CWE-122) that can lead to arbitrary code execution in the context of the current user. The vulnerability exists in the way the application processes certain design files and, if triggered, would allow an attacker to run malicious code with the privileges of the logged‑in user.
Affected Systems
Adobe Substance 3D Designer is the affected product; no specific version numbers are reported in the advisory.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity level, although the EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires a victim to open a malicious file, which implies user interaction. An attacker who succeeds would gain the ability to execute arbitrary code with the victim’s permissions, potentially compromising sensitive design data or system resources.
OpenCVE Enrichment