Impact
Substance3D Painter has an out-of-bounds write flaw that can lead to arbitrary code execution in the user’s security context. The vulnerability is a classic memory corruption bug, specifically relating to buffer overflow weaknesses (CWE-787). When triggered, it allows an attacker to overwrite adjacent memory and gain control of the program flow, potentially leading to full compromise of the affected user’s system.
Affected Systems
The impact is limited to Adobe Substance 3D Painter. No specific version information is listed in the CNA data, so all installations of Substance 3D Painter are potentially vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity vulnerability, and the lack of an EPSS score means current exploitation likelihood is unknown. The flaw requires user interaction: a malicious file must be opened, so it is considered an in-lieu of remote attack a local or social engineering scenario. The vulnerability is not listed in the CISA KEV catalog, but patching remains the recommended approach.
OpenCVE Enrichment