ZDI-CAN-20235: Adobe Substance 3D Stager USD File Parsing Use-After-Free Remote Code Execution Vulnerability
CVE-2023-26392
What is CVE-2023-26392?
Adobe Substance 3D Stager version 2.0.1 and earlier is affected by a Use After Free vulnerability that can allow arbitrary code execution in the context of the user currently running the application. Exploitation of this vulnerability necessitates user interaction, specifically requiring the victim to open a specially crafted malicious file that triggers the flaw. This serious security issue highlights the importance of maintaining updated software and exercising caution when handling untrusted files.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Substance3D - Stager <= 2.0.1
Substance3D - Stager <= unspecified
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved