Validate Your Inputs | Out-of-bounds Read (CWE-125)
CVE-2023-26371

7.8HIGH

Key Information:

Vendor

Adobe

Status
Vendor
CVE Published:
12 April 2023

What is CVE-2023-26371?

Adobe Dimension versions 3.4.8 and earlier contain an out-of-bounds read vulnerability that arises when processing specially crafted files. This flaw allows an attacker to potentially read beyond the limits of allocated memory, which may lead to unauthorized code execution within the context of the user who opened the malicious file. Exploiting this vulnerability requires the user to interact by opening the crafted file.

Affected Version(s)

Dimension <= 3.4.8

Dimension <= unspecified

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.