CVE-2023-29280: ZDI-CAN-20372: Adobe Substance 3D Painter PLY File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Adobe Substance 3D Painter versions 8.3.0 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-29280?
CVE-2023-29280 is classified as a critical severity vulnerability.
How do I fix CVE-2023-29280?
To fix CVE-2023-29280, update Adobe Substance 3D Painter to version 8.3.1 or later.
What type of vulnerability is CVE-2023-29280?
CVE-2023-29280 is an out-of-bounds read vulnerability.
What could an attacker achieve through CVE-2023-29280?
An attacker could potentially execute code in the context of the current user by exploiting CVE-2023-29280.
Which versions of Adobe Substance 3D Painter are affected by CVE-2023-29280?
Adobe Substance 3D Painter versions 8.3.0 and earlier are affected by CVE-2023-29280.