CVE-2024-20710: Adobe Substance 3D Stager v2.1.1 Vulnerability I
Adobe Substance 3D Stager versions 2.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Adobe Substance 3D Stagerto a version that resolves this vulnerability.Fixed in 2.1.3
Event History
Frequently Asked Questions
What is the severity of CVE-2024-20710?
The severity of CVE-2024-20710 is considered medium due to its potential impact on sensitive memory disclosure.
How do I fix CVE-2024-20710?
To fix CVE-2024-20710, update Adobe Substance 3D Stager to version 2.1.4 or later.
What systems are affected by CVE-2024-20710?
CVE-2024-20710 affects Adobe Substance 3D Stager versions 2.1.3 and earlier on supported operating systems.
Can CVE-2024-20710 be exploited remotely?
CVE-2024-20710 requires user interaction for exploitation, limiting remote attack vectors.
What are the implications of CVE-2024-20710?
The implications of CVE-2024-20710 include potential memory disclosure that could compromise application security.