CVE-2023-25877: Adobe Substance 3D Stager OBJ File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Adobe Substance 3D Stager versions 2.0.0 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-25877?
CVE-2023-25877 is classified with a severity level that indicates a potential for sensitive memory disclosure.
How do I fix CVE-2023-25877?
To mitigate CVE-2023-25877, users should update Adobe Substance 3D Stager to a version later than 2.0.0.
Is my version of Adobe Substance 3D Stager vulnerable to CVE-2023-25877?
Versions of Adobe Substance 3D Stager that are 2.0.0 and earlier are vulnerable to CVE-2023-25877.
What types of attacks could exploit CVE-2023-25877?
Exploitation of CVE-2023-25877 could allow an attacker to bypass mitigations such as ASLR through out-of-bounds read operations.
Does CVE-2023-25877 affect Windows or macOS?
CVE-2023-25877 specifically affects Adobe Substance 3D Stager on all platforms, including those running on Windows and macOS.