Out-of-Bounds Write Vulnerability in Substance3D Painter by Adobe
CVE-2024-49516

7.8HIGH

Key Information:

Vendor
Adobe
Vendor
CVE Published:
12 November 2024

Summary

The vulnerability presents an out-of-bounds write issue in Substance3D Painter versions up to 10.1.0. Exploitation of this flaw may allow for arbitrary code execution within the context of a user. Successful exploitation necessitates user interaction, specifically requiring that the user opens a specially crafted malicious file. As a result, this could pose a significant risk to user systems, emphasizing the need for caution when interacting with potentially harmful files.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.