Out-of-Bounds Write Vulnerability in Substance3D Stager by Adobe
CVE-2024-45141

7.8HIGH

Key Information:

Vendor
Adobe
Vendor
CVE Published:
9 October 2024

Summary

The vulnerability in Substance3D Stager allows an out-of-bounds write that may lead to arbitrary code execution. This flaw is particularly concerning, as it necessitates user interaction; specifically, users must open a malicious file for exploitation to occur. Versions of Substance3D Stager up to 3.0.3 are impacted by this security issue, elevating the risk for users who unknowingly engage with compromised files.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.