Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2024-12463
HistoryFeb 22, 2024 - 12:00 a.m.

Adobe Substance 3D Painter Buffer Overflow Vulnerability (CNVD-2024-12463)

2024-02-2200:00:00
China National Vulnerability Database
www.cnvd.org.cn
8
adobe
substance 3d painter
buffer overflow
vulnerability
remote attacker
arbitrary code
cnvd-2024-12463

7.5 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

28.3%

Adobe Substance 3D Painter is a 3D texturing application from the American company Audobee (Adobe). A buffer error vulnerability exists in Adobe Substance 3D Painter 9.1.1 and prior versions, which stems from an out-of-bounds read while parsing a carefully crafted file, which could result in a read beyond the end of an allocated memory structure. A remote attacker could exploit the vulnerability to execute arbitrary code.

CPENameOperatorVersion
adobe substance 3d painterle9.1.1

7.5 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

28.3%

Related for CNVD-2024-12463