CVE-2023-26372: ZDI-CAN-20284: Adobe Dimension USDZ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Adobe Dimension version 3.4.8 (and earlier) is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID of this Adobe Dimension vulnerability?
The vulnerability ID for this Adobe Dimension vulnerability is CVE-2023-26372.
What is the severity of CVE-2023-26372?
The severity of CVE-2023-26372 is high with a severity score of 7.8.
Which versions of Adobe Dimension are affected by CVE-2023-26372?
Adobe Dimension version 3.4.8 and earlier are affected by CVE-2023-26372.
What is the impact of CVE-2023-26372?
CVE-2023-26372 could result in arbitrary code execution in the context of the current user.
How can CVE-2023-26372 be exploited?
Exploitation of CVE-2023-26372 requires user interaction in that a victim must open a malicious file.
How can I fix CVE-2023-26372?
To fix CVE-2023-26372, update Adobe Dimension to version 3.4.9 or later.