PT-2024-7320 · Adobe · Substance3D - Sampler

Published

2024-08-13

·

Updated

2024-10-23

·

CVE-2024-47459

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Substance3D - Sampler versions 4.5 and earlier
Description: The issue is related to a null pointer dereference vulnerability. Exploitation of this vulnerability could lead to an application denial-of-service (DoS) condition, allowing an attacker to crash the application. This requires user interaction, where a victim must open a malicious file. The estimated number of potentially affected devices and details about real-world incidents are not provided.
Recommendations: For Substance3D - Sampler versions 4.5 and earlier, upgrade to a version later than 4.5 to resolve the issue. As a temporary workaround, consider avoiding the opening of suspicious or malicious files with the affected software until a patch is applied. Restricting access to potentially vulnerable components or modules within the software may also help minimize the risk of exploitation.

Fix

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

BDU:2024-08675
CVE-2024-47459

Affected Products

Substance3D - Sampler