Impact
The vulnerability is a stack-based buffer overflow (CWE-121) in Substance3D – Modeler that can be triggered by opening a specially crafted file. This flaw allows an attacker to execute arbitrary code within the victim’s user context, compromising confidentiality, integrity, and availability of the host system.
Affected Systems
Adobe’s Substance3D – Modeler is affected. No specific version numbers were provided in the advisory, so all installations of the product that match the product name should be considered at risk until a patch is applied.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity vulnerability. The attacker must supply and open a malicious file, so user interaction is required; it is not a remote exploitation vector. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the high severity combined with the requirement for user action makes this a significant threat for environments where users may receive or handle untrusted files.
OpenCVE Enrichment