PT-2023-6322 · Adobe · Substance3D - Stager

Published

2023-04-11

·

Updated

2023-04-19

·

CVE-2023-26388

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Adobe Substance 3D Stager version 2.0.1 and earlier
Description The issue is related to improper input validation, which could result in arbitrary code execution in the context of the current user. Exploitation requires user interaction, where a victim must open a malicious file. This can also be described as a memory corruption vulnerability, potentially allowing an attacker to execute arbitrary code using a specially crafted file.
Recommendations For Adobe Substance 3D Stager version 2.0.1 and earlier, consider avoiding the use of potentially malicious files until a patch is available. As a temporary workaround, restrict the opening of files from untrusted sources to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Access of Memory Location After End of Buffer

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-07034
CVE-2023-26388
ZDI-23-414

Affected Products

Substance3D - Stager