CVE-2024-47435: Substance3D - Painter | Out-of-bounds Read (CWE-125)
Published Nov 12, 2024
·Updated
Substance3D - Painter versions 10.1.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
1 affected component
Adobe Substance 3D Painter<10.1.1
Event History
Nov 12, 2024
CVE Published
via MITRE·08:02 PM
Data Sourced
via MITRE·08:02 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-47435?
CVE-2024-47435 has a critical severity level due to the potential for sensitive memory disclosure.
2
How do I fix CVE-2024-47435?
To fix CVE-2024-47435, upgrade Adobe Substance 3D Painter to version 10.1.1 or later.
3
Who is affected by CVE-2024-47435?
Users of Adobe Substance 3D Painter versions 10.1.0 and earlier are affected by CVE-2024-47435.
4
What type of vulnerability is CVE-2024-47435?
CVE-2024-47435 is an out-of-bounds read vulnerability.
5
Can CVE-2024-47435 be exploited without user interaction?
Exploitation of CVE-2024-47435 requires user interaction.