PT-2023-7696 · Adobe · Dimension
CVE-2023-47078
·
Publicado
2023-09-27
·
Atualizado
2023-12-15
CVSS v3.1
5.5
Média
| Vetor | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Adobe Dimension versions 3.4.10 and earlier
Description
The issue is related to an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. This vulnerability can be exploited by an attacker to bypass mitigations such as ASLR. Exploitation requires user interaction, where a victim must open a malicious file, specifically a USD file, which can allow an attacker to gain unauthorized access to protected information.
Recommendations
For Adobe Dimension versions 3.4.10 and earlier, update to a version later than 3.4.10 to resolve the issue. As a temporary workaround, consider avoiding the use of USD files or restricting access to them until a patch is available. Additionally, be cautious when opening files from untrusted sources to minimize the risk of exploitation.
Correção
Out of bounds Read
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Dimension