Impact
Substance3D - Sampler contains a heap‑based buffer overflow (CWE‑122) that can be triggered by a malicious file. When processed, the overflow may allow the attacker to inject arbitrary code into the application’s memory space and execute it with the privileges of the user running the software.
Affected Systems
The affected vendor is Adobe, with the product Adobe Substance 3D Sampler. No specific version ranges are listed in the public data, so all current and future releases should be considered potentially vulnerable until an official update is released.
Risk and Exploitability
The vulnerability has a CVSS score of 7.8, indicating a high impact if exploited. The EPSS score is not available, and the flaw is not listed in the CISA KEV catalog, suggesting the exploitation risk is not currently known to be widespread. The attack vector requires user interaction, as a victim must open a malicious file; therefore the exploitation probability is tied to the likelihood of a user receiving and opening such a payload.
OpenCVE Enrichment