CVE-2023-26373: Adobe Dimension has an arbitrary address write vulnerability when parsing USDZ files
Adobe Dimension version 3.4.8 (and earlier) is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-26373?
CVE-2023-26373 is an out-of-bounds write vulnerability in Adobe Dimension version 3.4.8 (and earlier) that could lead to arbitrary code execution.
How can this vulnerability be exploited?
This vulnerability can be exploited by opening a malicious file, requiring user interaction.
Which software versions are affected by CVE-2023-26373?
Adobe Dimension version 3.4.8 (and earlier) is affected by this vulnerability.
What is the severity of CVE-2023-26373?
CVE-2023-26373 has a severity score of 7.8, categorized as high.
How can I mitigate CVE-2023-26373?
To mitigate this vulnerability, users should update Adobe Dimension to a version later than 3.4.8.