First published: Wed Dec 13 2023(Updated: )
Adobe Substance 3D Stager versions 2.1.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Adobe Substance 3D Stager | <=2.1.1 | |
Any of | ||
Apple macOS | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-47081 is classified as a high-severity vulnerability due to its potential to expose sensitive memory.
To fix CVE-2023-47081, users should update Adobe Substance 3D Stager to version 2.1.2 or later.
An attacker could exploit CVE-2023-47081 to bypass security mitigations like ASLR and gain access to sensitive memory.
CVE-2023-47081 affects Adobe Substance 3D Stager version 2.1.1 and earlier.
Yes, CVE-2023-47081 does not affect Adobe Substance 3D Stager when running on unsupported operating systems like Apple macOS or Microsoft Windows.