CVE-2024-34126: ZDI-CAN-24028: Adobe Dimension USD File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Published Aug 14, 2024
·Updated
Dimension versions 3.4.11 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
1 affected component
Adobe Dimension<=3.4.11
Event History
Aug 14, 2024
CVE Published
via MITRE·02:55 PM
Data Sourced
via MITRE·02:55 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-34126?
CVE-2024-34126 has been rated as high severity due to its potential for sensitive memory disclosure.
2
How do I fix CVE-2024-34126?
To fix CVE-2024-34126, update Adobe Dimension to version 3.4.12 or later.
3
What are the potential impacts of CVE-2024-34126?
Exploitation of CVE-2024-34126 could allow attackers to bypass security mitigations and disclose sensitive information.
4
Is user interaction required to exploit CVE-2024-34126?
Yes, exploiting CVE-2024-34126 requires user interaction.
5
Which versions of Adobe Dimension are affected by CVE-2024-34126?
Adobe Dimension versions 3.4.11 and earlier are affected by CVE-2024-34126.