CVE-2023-26394: ZDI-CAN-20236: Adobe Substance 3D Stager USD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Adobe Substance 3D Stager version 2.0.1 (and earlier) is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-26394?
CVE-2023-26394 is considered to have a high severity due to its potential for arbitrary code execution.
How do I fix CVE-2023-26394?
To fix CVE-2023-26394, you should update Adobe Substance 3D Stager to version 2.0.2 or later.
What impact could CVE-2023-26394 have on my system?
Exploitation of CVE-2023-26394 could lead to arbitrary code execution, compromising the security of the affected system.
Is user interaction required to exploit CVE-2023-26394?
Yes, exploitation of CVE-2023-26394 requires user interaction as the victim must open a malicious file.
Which versions of Adobe Substance 3D Stager are affected by CVE-2023-26394?
Adobe Substance 3D Stager versions up to and including 2.0.1 are affected by CVE-2023-26394.