First published: Tue Mar 28 2023(Updated: )
Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Dimension | <3.4.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-26346 is an out-of-bounds read vulnerability affecting Adobe Dimension versions 3.4.7 and earlier.
CVE-2023-26346 has a severity rating of 5.5, which is considered medium.
CVE-2023-26346 allows for disclosure of sensitive memory and the bypassing of mitigations such as ASLR in Adobe Dimension versions 3.4.7 and earlier.
Exploiting CVE-2023-26346 requires user interaction, such as a victim opening a malicious file or visiting a specially crafted website.
Yes, upgrading to Adobe Dimension version 3.4.8 or later will fix CVE-2023-26346.