ZDI-CAN-20235: Adobe Substance 3D Stager USD File Parsing Use-After-Free Remote Code Execution Vulnerability
CVE-2023-26392
7.8HIGH
Summary
Adobe Substance 3D Stager version 2.0.1 and earlier is affected by a Use After Free vulnerability that can allow arbitrary code execution in the context of the user currently running the application. Exploitation of this vulnerability necessitates user interaction, specifically requiring the victim to open a specially crafted malicious file that triggers the flaw. This serious security issue highlights the importance of maintaining updated software and exercising caution when handling untrusted files.
Affected Version(s)
Substance3D - Stager <= 2.0.1
Substance3D - Stager <= unspecified
References
EPSS Score
7% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved