Heap-based Buffer Overflow in Substance3D Stager by Adobe
CVE-2024-45143

7.8HIGH

Key Information:

Vendor
Adobe
Vendor
CVE Published:
9 October 2024

Summary

The Heap-based Buffer Overflow vulnerability in Adobe's Substance3D Stager allows for potential arbitrary code execution when a user interacts with a malicious file. Specifically, versions 3.0.3 and earlier are susceptible, requiring user engagement for exploitation. This vulnerability highlights the risks associated with opening untrusted files and emphasizes the need for users to remain vigilant about the files they choose to open. Protecting oneself from this vulnerability involves avoiding interactions with unknown or suspicious files and ensuring that software is updated with the latest security patches.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.