Impact
Substance3D Modeler contains an out‑of‑bounds write flaw that allows a crafted file to corrupt memory and execute arbitrary code in the context of the user who opens it. The vulnerability permits the attacker to overwrite critical data structures or return addresses, enabling the injection of malicious payloads. Because the code runs with the user’s privileges, a successful exploitation could lead to local account compromise, data theft, or further lateral movement in an environment where the user has administrative or high‑level access.
Affected Systems
Adobe’s Substance3D Modeler is vulnerable. No specific version set is listed in the CNA data; the flaw applies to the releases of Substance3D Modeler that are patched only after the Adobe security advisory is applied. The advisory can be found on Adobe’s support site.
Risk and Exploitability
The CVSS score for the issue is 7.8, indicating a high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the victim to open a malicious file, which means the attack vector is user‑interaction based. The lack of remote network or web‑based exploitation reduces the immediate risk of widespread attacks, but users who routinely open or import files from untrusted sources remain at significant risk of arbitrary code execution.
OpenCVE Enrichment