Impact
The vulnerability is a heap-based buffer overflow that can allow an attacker to execute arbitrary code in the user's context. Exploitation requires a victim to open a maliciously crafted file, meaning user interaction is necessary.
Affected Systems
Adobe Substance 3D Designer is the impacted product. The advisory does not list specific vulnerable versions, so any installation of Substance 3D Designer that has not applied the vendor's security patch may be affected.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity level. EPSS is not available, and the issue is not listed in the CISA KEV catalog, suggesting no known active exploits yet. The likely attack vector is a file-based exploit where a malicious file is opened by the user, triggering the heap overflow and code execution.
OpenCVE Enrichment