First published: Mon Mar 27 2023(Updated: )
Adobe Substance 3D Stager versions 2.0.0 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Substance 3D Stager | <=2.0.0 | |
Apple iOS and macOS | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-25877 is classified with a severity level that indicates a potential for sensitive memory disclosure.
To mitigate CVE-2023-25877, users should update Adobe Substance 3D Stager to a version later than 2.0.0.
Versions of Adobe Substance 3D Stager that are 2.0.0 and earlier are vulnerable to CVE-2023-25877.
Exploitation of CVE-2023-25877 could allow an attacker to bypass mitigations such as ASLR through out-of-bounds read operations.
CVE-2023-25877 specifically affects Adobe Substance 3D Stager on all platforms, including those running on Windows and macOS.