CVE-2023-26410: ZDI-CAN-20309: Adobe Substance 3D Designer USD File Parsing Use-After-Free Remote Code Execution Vulnerability
Adobe Substance 3D Designer version 12.4.0 (and earlier) is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-26410?
CVE-2023-26410 has a severity rating that indicates a potential for arbitrary code execution through a Use After Free vulnerability.
How do I fix CVE-2023-26410?
To remediate CVE-2023-26410, users should update Adobe Substance 3D Designer to the latest version released after 12.4.0.
What platforms are affected by CVE-2023-26410?
CVE-2023-26410 affects Adobe Substance 3D Designer version 12.4.0 and earlier, regardless of the underlying operating system.
What types of attacks can exploit CVE-2023-26410?
Exploitation of CVE-2023-26410 requires user interaction, specifically opening a malicious file that triggers the vulnerability.
Who is impacted by CVE-2023-26410?
Users of Adobe Substance 3D Designer version 12.4.0 and earlier are at risk of exploitation from CVE-2023-26410.