ZDI-CAN-20366: Adobe Substance 3D Painter USDC File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
CVE-2023-29274
What is CVE-2023-29274?
Adobe Substance 3D Painter versions 8.3.0 and earlier are susceptible to an out-of-bounds read vulnerability that occurs when parsing specially crafted files. This vulnerability could enable an attacker to read data beyond the allocated memory limits, potentially leading to arbitrary code execution within the context of the current user. Exploiting this vulnerability necessitates user interaction, as it requires the user to open a malicious file. Therefore, vigilance is essential when handling files from untrusted sources to mitigate risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Substance3D - Painter <= 8.3.0
Substance3D - Painter <= unspecified
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved