CVE-2024-20713: Adobe Substance 3D Stager v2.1.1 Vulnerability IV
Adobe Substance 3D Stager versions 2.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Adobe Substance 3D Stagerto a version that resolves this vulnerability.Fixed in 2.1.3
Event History
Frequently Asked Questions
What is the severity of CVE-2024-20713?
CVE-2024-20713 is classified as a high-severity vulnerability due to its potential for memory disclosure.
How do I fix CVE-2024-20713?
To fix CVE-2024-20713, update Adobe Substance 3D Stager to version 2.1.4 or later.
What can an attacker achieve by exploiting CVE-2024-20713?
Exploiting CVE-2024-20713 allows an attacker to disclose sensitive memory and potentially bypass security mitigations like ASLR.
Which versions of Adobe Substance 3D Stager are affected by CVE-2024-20713?
Adobe Substance 3D Stager versions 2.1.3 and earlier are affected by CVE-2024-20713.
Do I need to worry about CVE-2024-20713 if I'm using macOS or Windows?
CVE-2024-20713 specifically affects installations of Adobe Substance 3D Stager and does not impact macOS or Windows systems directly.