CVE-2023-38211: ZDI-CAN-21078: Adobe Dimension GLB File Parsing Use-After-Free Remote Code Execution Vulnerability
Published Aug 9, 2023
·Updated
Adobe Dimension version 3.4.9 is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
3 affected components
Adobe Dimension<=3.4.9
macOS
Microsoft Windows
Remediation
Event History
Aug 9, 2023
CVE Published
via MITRE·08:23 AM
Data Sourced
via MITRE·08:23 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-38211?
CVE-2023-38211 is a Use After Free vulnerability in Adobe Dimension version 3.4.9.
2
What is the impact of CVE-2023-38211?
The impact of CVE-2023-38211 is arbitrary code execution in the context of the current user.
3
How can CVE-2023-38211 be exploited?
Exploitation of CVE-2023-38211 requires user interaction in that a victim must open a malicious file.
4
Which software versions are affected by CVE-2023-38211?
Adobe Dimension version 3.4.9 is affected by CVE-2023-38211.
5
How severe is CVE-2023-38211?
CVE-2023-38211 has a severity rating of 7.8 (high).
6
How can I fix CVE-2023-38211?
To fix CVE-2023-38211, update Adobe Dimension to a version that is not affected by the vulnerability.