CVE-2024-47440: Substance3D - Painter | Out-of-bounds Read (CWE-125)
Published Nov 12, 2024
·Updated
Substance3D - Painter versions 10.1.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
1 affected component
Adobe Substance 3D Painter<10.1.1
Event History
Nov 12, 2024
CVE Published
via MITRE·08:02 PM
Data Sourced
via MITRE·08:02 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-47440?
CVE-2024-47440 has a high severity rating due to potential disclosure of sensitive memory.
2
How do I fix CVE-2024-47440?
To fix CVE-2024-47440, users should update Adobe Substance 3D Painter to version 10.1.1 or later.
3
What types of vulnerabilities does CVE-2024-47440 represent?
CVE-2024-47440 represents an out-of-bounds read vulnerability.
4
Can CVE-2024-47440 be exploited without user interaction?
No, exploitation of CVE-2024-47440 requires user interaction.
5
What could an attacker achieve by exploiting CVE-2024-47440?
An attacker could leverage CVE-2024-47440 to bypass mitigations such as ASLR.