Impact
The vulnerability is an out-of-bounds write in Substance3D Modeler that could allow an attacker to execute arbitrary code within the victim’s user context. This flaw occurs when processing a malicious model file, and it can lead to full compromise of the user’s system if exploited. The weakness aligns with CWE‑787, which concerns improper bounds checking leading to buffer overflows.
Affected Systems
The affected vendor is Adobe, specifically its Substance3D Modeler application. No specific version numbers are provided in the advisory, so all releases currently in use are potentially vulnerable until an official patch is applied.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity. Because exploitation requires the user to open a crafted file, the attack vector is local file and user interaction. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting it is not a commonly exploited vulnerability today, but still poses a serious risk if a malicious file is introduced.
OpenCVE Enrichment