Impact
An out‑of‑bounds write allows attacker‑controlled data to corrupt memory and execute arbitrary code in the context of the user who opens a malicious file. The flaw could let a malicious actor run any code the authenticated user can, exposing the system to full compromise.
Affected Systems
Adobe Substance3D -- Modeler is affected. No specific release numbers are disclosed in the advisory.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.8, indicating a high chance of serious impact. The advisory notes that exploitation requires user interaction – the victim must open a crafted file. EPSS data is not available, and the issue is not listed in the CISA KEV catalog, so the likelihood of widespread automated exploitation appears limited. Nonetheless, because of the potential for full code execution, the risk is significant for any environment that allows users to open arbitrary model files.
OpenCVE Enrichment