CVE-2026-21344: Substance3D - Stager | Out-of-bounds Read (CWE-125)
Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21344?
The severity of CVE-2026-21344 is rated as high due to the potential for exploitation that could lead to arbitrary memory reads.
How do I fix CVE-2026-21344?
To fix CVE-2026-21344, upgrade to Substance3D Stager version 3.1.7 or later, which addresses the out-of-bounds read vulnerability.
What types of attacks can exploit CVE-2026-21344?
An attacker could exploit CVE-2026-21344 by crafting a malicious file that, when processed by vulnerable versions of Substance3D Stager, results in unauthorized memory access.
Which versions of Substance3D Stager are affected by CVE-2026-21344?
Substance3D Stager versions 3.1.6 and earlier are affected by CVE-2026-21344.
Can CVE-2026-21344 lead to data leakage?
Yes, CVE-2026-21344 can potentially lead to data leakage by allowing attackers to access sensitive information beyond allocated memory.