ZDI-CAN-20366: Adobe Substance 3D Painter USDC File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
CVE-2023-29274

7.8HIGH

Key Information:

Vendor

Adobe

Vendor
CVE Published:
11 May 2023

What is CVE-2023-29274?

Adobe Substance 3D Painter versions 8.3.0 and earlier are susceptible to an out-of-bounds read vulnerability that occurs when parsing specially crafted files. This vulnerability could enable an attacker to read data beyond the allocated memory limits, potentially leading to arbitrary code execution within the context of the current user. Exploiting this vulnerability necessitates user interaction, as it requires the user to open a malicious file. Therefore, vigilance is essential when handling files from untrusted sources to mitigate risk.

Affected Version(s)

Substance3D - Painter <= 8.3.0

Substance3D - Painter <= unspecified

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.