Impact
A heap-based buffer overflow in Adobe Substance 3D Painter enables an attacker to execute arbitrary code within the context of the current user. The vulnerability requires the victim to open a crafted file, so user interaction is necessary for exploitation.
Affected Systems
Adobe Substance 3D Painter is affected; no specific version numbers are supplied in the advisory.
Risk and Exploitability
The CVSS score of 7.8 indicates a high impact once triggered. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, implying no widely known public exploits at this time. Exploitation requires that the user open a malicious file, so the attack vector is through content that the user chooses to load into Substance 3D Painter.
OpenCVE Enrichment