PT-2026-7423 · Adobe · Substance3D - Stager

Jann Horn

·

Publicado

2026-02-10

·

Atualizado

2026-02-10

·

CVE-2026-21342

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Substance3D - Stager versions 3.1.6 and earlier
Description The software contains a flaw that allows for writing data outside the intended memory boundaries. Successful exploitation of this issue could lead to arbitrary code execution with the privileges of the current user. User interaction is required for exploitation, specifically, a user must open a specially crafted malicious file.
Recommendations Update Substance3D - Stager to a version later than 3.1.6.

Correção

Memory Corruption

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-01893
CVE-2026-21342

Produtos afetados

Substance3D - Stager