Impact
A heap-based buffer overflow in Adobe Substance 3D Painter allows an attacker to run arbitrary code in the context of the user who opens a malicious file. This flaw matches CWE-122 and can lead to a compromise of confidentiality, integrity, or availability if exploited.
Affected Systems
Adobe Substance 3D Painter. No specific version information is provided, but the vulnerability applies to all installations affected by the Adobe advisory linked above.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity. Exploitation requires user interaction to open a crafted file, meaning it is a local attack vector. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting it has not been widely observed in the wild yet, but the potential for damage remains significant if an end‑user opens a malicious file.
OpenCVE Enrichment