Impact
This vulnerability is an out‑of‑bounds write in Adobe Substance 3D Sampler that can lead to arbitrary code execution. The flaw allows an attacker to corrupt data beyond an allocated buffer, potentially enabling the execution of malicious code in the victim’s user context. Because the vulnerability lies in memory handling during file processing, correct error handling would prevent the exploit.
Affected Systems
The affected product is Adobe Substance 3D Sampler. Version information is not disclosed in the current advisory, so any installed instance may be vulnerable until the vendor releases a fix.
Risk and Exploitability
The CVSS score of 7.8 indicates a high impact severity, while no EPSS data is available. The flaw is not part of the CISA KEV catalog. Exploit requires user interaction; the attacker must craft a malicious file and persuade a user to open it. The attack surface is limited to those who have downloaded or received such a file, but the resulting code execution would run with the victim’s privileges.
OpenCVE Enrichment