Impact
Substance3D Painter is vulnerable to a heap-based buffer overflow that can lead to arbitrary code execution in the context of the user who opens a malicious file. The flaw arises when processing specially crafted document data, enabling an attacker to overflow an internal buffer. This overflow can be triggered by user interaction, specifically by opening a file that is crafted to exploit the vulnerability.
Affected Systems
All installations of Adobe Substance 3D Painter are affected, as the CNA does not specify a fixed version; administrations should assume that every current release prior to the advisory patch is susceptible.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity, and the lack of an EPSS score means current exploit prevalence is unknown. Since the vulnerability requires user interaction to open a malicious file, the attack vector is local but must be facilitated by social engineering or phishing. The vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation, but the potential for remote code execution warrants cautious mitigation.
OpenCVE Enrichment