Impact
Substance3D Painter is vulnerable to an out‑of‑bounds read that allows an attacker to read sensitive memory contents. The flaw can expose confidential data but does not allow arbitrary code execution or system compromise. The weakness is a classic boundary validation error, as identified by CWE‑125.
Affected Systems
Adobe Substance 3D Painter products are affected. The vulnerability does not list specific version ranges, so all installations that have not applied the latest security update are potentially at risk.
Risk and Exploitability
The CVSS score of 5.5 indicates a medium‑severity disclosure risk. EPSS is not available, and the vulnerability is not listed in CISA KEV, so no evidence suggests active exploitation. The attack requires the victim to open a malicious file, meaning the vector is local and user‑initiated. In the absence of further exploitation reports, the risk remains moderate but tangible for environments that handle sensitive data.
OpenCVE Enrichment