Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2024-12464
HistoryFeb 22, 2024 - 12:00 a.m.

Adobe Substance 3D Painter Buffer Overflow Vulnerability (CNVD-2024-12464)

2024-02-2200:00:00
China National Vulnerability Database
www.cnvd.org.cn
9
adobe substance 3d painter
buffer overflow
vulnerability
audobee
arbitrary code
execution
unauthorized commands
system privileges
illegal operations
cnvd-2024-12464

8 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

28.3%

Adobe Substance 3D Painter is a 3D texturing application from the American company Audobee (Adobe). A buffer overflow vulnerability exists in Adobe Substance 3D Painter 9.1.1 and prior versions, which stems from the presence of an out-of-bounds write that could lead to the execution of arbitrary code in the context of the current user. An attacker can exploit the vulnerability to execute unauthorized commands, which can be used to gain system privileges and consequently perform various illegal operations.

CPENameOperatorVersion
adobe substance 3d painterle9.1.1

8 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

28.3%

Related for CNVD-2024-12464