Impact
The vulnerability is an out-of-bounds write condition in Adobe Substance 3D Painter that can lead to arbitrary code execution in the current user’s context. This flaw allows an attacker to run malicious instructions after the user opens a crafted file. The weakness is identified as CWE‑787, a classic buffer overflow that undermines data integrity and confidentiality for the affected user.
Affected Systems
Adobe’s Substance 3D Painter is the only product listed. No specific version numbers are provided in the current entry; security teams should verify installations against the vendor’s advisory and determine whether their current builds contain the flaw.
Risk and Exploitability
The CVSS score of 7.8 reflects a high risk of compromise, and the vulnerability is listed as not in the CISA Key‑Exploited Vulnerabilities catalog. EPSS data is unavailable, so precise exploitation probability cannot be quantified. However, the flaw requires a victim to open a malicious file, indicating that the attack vector is user‑initiated and generally local or shared. Once executed, the attacker gains the privileges of the victim, potentially compromising the entire system and any data accessed by that user.
OpenCVE Enrichment