CVE-2024-20711: Adobe Substance 3D Stager v2.1.1 Vulnerability VII
Adobe Substance 3D Stager versions 2.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-20711?
CVE-2024-20711 has been classified with a severity rating that indicates a significant risk due to potential sensitive memory disclosure.
How do I fix CVE-2024-20711?
To address CVE-2024-20711, update Adobe Substance 3D Stager to version 2.1.4 or later, where the vulnerability is resolved.
What could an attacker achieve by exploiting CVE-2024-20711?
An attacker exploiting CVE-2024-20711 could potentially bypass security mitigations like ASLR and gain access to sensitive information.
Which versions of Adobe Substance 3D Stager are affected by CVE-2024-20711?
Adobe Substance 3D Stager versions 2.1.3 and earlier are affected by CVE-2024-20711.
Is an update to macOS or Windows required to fix CVE-2024-20711?
No, the fix for CVE-2024-20711 only requires updating Adobe Substance 3D Stager, as it does not directly involve operating system updates.