Out-of-bounds Write Vulnerability in Substance3D Stager by Adobe
CVE-2024-45140

7.8HIGH

Key Information:

Vendor
Adobe
Vendor
CVE Published:
9 October 2024

Summary

Substance3D Stager versions 3.0.3 and earlier contain an out-of-bounds write vulnerability that can be exploited to achieve arbitrary code execution in the context of the user. This vulnerability necessitates user interaction, specifically when the user opens a crafted malicious file that triggers the exploit. Users of affected versions should exercise caution and ensure they are aware of the possible risks associated with opening unknown or untrusted files.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.