ZDI-23-1777: Adobe Dimension GLB File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Dimension. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2023-47061.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-1777?
The severity of ZDI-23-1777 is assessed as moderate, focusing on sensitive information disclosure.
How do I fix ZDI-23-1777?
To fix ZDI-23-1777, users should update to the latest version of Adobe Dimension as provided by Adobe.
What are the potential impacts of ZDI-23-1777?
The potential impacts of ZDI-23-1777 include unauthorized access to sensitive information if exploited.
Is user interaction necessary for ZDI-23-1777 to be exploited?
Yes, user interaction is required for ZDI-23-1777 as the target must visit a malicious page or open a malicious file.
Which software is affected by ZDI-23-1777?
ZDI-23-1777 affects installations of Adobe Dimension.