ZDI-CAN-20310: Adobe Substance 3D Designer USDC File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
CVE-2023-26398

7.8HIGH

Key Information:

Vendor
Adobe
Vendor
CVE Published:
13 April 2023

Summary

Adobe Substance 3D Designer, up to version 12.4.0, contains an out-of-bounds read vulnerability. This occurs when the application processes a specially crafted file, potentially permitting an attacker to read data beyond the allocated memory buffer. The exploitation of this vulnerability necessitates that a user interacts with a malicious file, thereby increasing the risk of arbitrary code execution in the context of the user. It is crucial for users to be vigilant and avoid opening suspicious files that may exploit this security issue.

Affected Version(s)

Substance3D - Designer <= 12.4.0

Substance3D - Designer <= unspecified

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.