Impact
Substance3D Designer contains a heap‑based buffer overflow that allows an attacker to execute arbitrary code in the context of the currently logged user. The flaw occurs when the application processes a specially crafted file, enabling the attacker to corrupt memory and redirect program flow. This type of vulnerability is categorized as CWE‑122 and can lead to full system compromise if exploited successfully.
Affected Systems
The affected product is Adobe Substance 3D Designer, an application used for 3D modeling and design. Specific version information is not supplied in the advisory, so all releases that include the vulnerable code path should be considered potentially impacted until a vendor patch is released.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity. Although the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, the requirement for user interaction—namely opening a malicious file—provides a clear attack path. If an attacker can deliver a crafted file to a target user, the heap overflow can be triggered, leading to arbitrary code execution without additional privileges.
OpenCVE Enrichment