ZDI-CAN-20366: Adobe Substance 3D Painter USDC File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
CVE-2023-29274
7.8HIGH
What is CVE-2023-29274?
Adobe Substance 3D Painter versions 8.3.0 and earlier are susceptible to an out-of-bounds read vulnerability that occurs when parsing specially crafted files. This vulnerability could enable an attacker to read data beyond the allocated memory limits, potentially leading to arbitrary code execution within the context of the current user. Exploiting this vulnerability necessitates user interaction, as it requires the user to open a malicious file. Therefore, vigilance is essential when handling files from untrusted sources to mitigate risk.
Affected Version(s)
Substance3D - Painter <= 8.3.0
Substance3D - Painter <= unspecified