Substance3D - Painter | Out-of-bounds Write (CWE-787)
CVE-2024-49519

7.8HIGH

Key Information:

Vendor
Adobe
Vendor
CVE Published:
12 November 2024

Summary

The vulnerability in Adobe Substance3D Painter is characterized by an out-of-bounds write issue that permits arbitrary code execution in the context of the user. This security flaw necessitates user action, as an attacker must convince the user to open a specially crafted malicious file. The exploitation of this vulnerability raises significant concerns for users, particularly those utilizing affected versions, as it could lead to unauthorized operations on their systems.

Affected Version(s)

Substance3D - Painter 0 <= 10.1.0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.