CVE-2023-26415: ZDI-CAN-20317: Adobe Substance 3D Designer DAE File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Adobe Substance 3D Designer version 12.4.0 (and earlier) is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-26415?
CVE-2023-26415 is considered a critical vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2023-26415?
To fix CVE-2023-26415, update Adobe Substance 3D Designer to the latest version released after 12.4.0.
What could be the impact of exploiting CVE-2023-26415?
Exploitation of CVE-2023-26415 could lead to unauthorized access and execution of arbitrary commands on the affected system.
What requirements exist for exploiting CVE-2023-26415?
Exploitation of CVE-2023-26415 requires user interaction, specifically opening a malicious file.
Which versions of Adobe Substance 3D Designer are affected by CVE-2023-26415?
Adobe Substance 3D Designer versions 12.4.0 and earlier are affected by CVE-2023-26415.