Impact
Substance3D Designer is vulnerable to an out‑of‑bounds write that could allow arbitrary code execution in the context of the user. The flaw arises when the application processes a malicious file, resulting in a buffer overflow that writes data outside the intended memory region. This category of vulnerability is identified as CWE-787.
Affected Systems
Adobe Substance 3D Designer is affected. No specific product versions are listed in the vulnerability data, so any installation of the product may need to be monitored until a vendor update is released.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.8, indicating a high severity level. The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog. The attack vector is user interaction, as a victim must open a malicious file for exploitation. Because the flaw enables arbitrary code execution, the impact spans confidentiality, integrity, and availability of the compromised system. The lack of publicly available exploit statistics means that the real‑world exploitation risk is uncertain but potentially significant for users who accept untrusted files.
OpenCVE Enrichment