First published: Wed Jan 10 2024(Updated: )
Adobe Substance 3D Stager versions 2.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Adobe Substance 3D Stager | <=2.1.3 | |
Any of | ||
macOS | ||
Microsoft Windows Operating System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-20710 is considered medium due to its potential impact on sensitive memory disclosure.
To fix CVE-2024-20710, update Adobe Substance 3D Stager to version 2.1.4 or later.
CVE-2024-20710 affects Adobe Substance 3D Stager versions 2.1.3 and earlier on supported operating systems.
CVE-2024-20710 requires user interaction for exploitation, limiting remote attack vectors.
The implications of CVE-2024-20710 include potential memory disclosure that could compromise application security.