Out-of-Bounds Write Vulnerability in Substance3D - Painter by Adobe
CVE-2024-47433

7.8HIGH

Key Information:

Vendor
Adobe
Vendor
CVE Published:
12 November 2024

Summary

An out-of-bounds write vulnerability exists in Substance3D - Painter that affects versions 10.1.0 and earlier. This vulnerability allows attackers to perform arbitrary code execution within the context of the current user. Exploitations necessitate user interaction whereby the victim must open a specially crafted file. This creates potential risks for users, highlighting the importance of vigilance and updating to mitigate exposure.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.