CVE-2023-26327: ZDI-CAN-20217: Adobe Dimension GLTF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for Adobe Dimension?
The vulnerability ID for Adobe Dimension is CVE-2023-26327.
What is the severity level of CVE-2023-26327?
The severity level of CVE-2023-26327 is high.
What can an attacker do with CVE-2023-26327?
An attacker can leverage CVE-2023-26327 to bypass mitigations and potentially disclose sensitive memory.
Which versions of Adobe Dimension are affected by CVE-2023-26327?
Adobe Dimension versions 3.4.7 and earlier are affected by CVE-2023-26327.
Is Apple macOS or Microsoft Windows vulnerable to CVE-2023-26327?
No, Apple macOS and Microsoft Windows are not vulnerable to CVE-2023-26327.
How can I fix CVE-2023-26327?
To fix CVE-2023-26327, update Adobe Dimension to version 3.4.8 or later.