Impact
Substance3D Painter suffers from a heap-based buffer overflow that can lead to arbitrary code execution in the context of the current user. The vulnerability is a classic example of overflow in memory allocation leading to untrusted data being written beyond a buffer boundary (CWE-122). Attackers can craft a malicious file that, when opened, triggers the overflow and allows execution of attacker-supplied payloads.
Affected Systems
Any installation of Adobe Substance 3D Painter is affected; the advisory lists the product but does not specify a particular version range, indicating that all current releases may be vulnerable until patched.
Risk and Exploitability
The CVSS score of 7.8 classifies the issue as high severity. Exploitation requires user interaction; a victim must open a malicious file, so the attack vector is local or social engineering involving file-based delivery. The EPSS score is not available, making precise usage probability uncertain, and the vulnerability is not listed in CISA’s KEV catalog. Nevertheless, the potential for arbitrary code execution warrants cautious mitigation.
OpenCVE Enrichment