Description
Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVSS breakdown
CVSS 3.1
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected products
- Adobe / Adobe Substance 3D Designer0 – 15.1.0
- Adobe / Adobe Substance 3D Designer16.0.1 – 16.0.1
- Adobe / substance_3d_designer15.1.0
- Adobe / Substance3D - Designer0 – 15.1.0
References
Updated 14m ago · 8 sources