ZDI-23-1780: Adobe Dimension USD File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Dimension. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2023-47078.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-1780?
The vulnerability ZDI-23-1780 has a CVSS score indicating it is of moderate severity.
How do I fix ZDI-23-1780?
To fix ZDI-23-1780, ensure you update Adobe Dimension to the latest version provided by Adobe.
What kind of information can ZDI-23-1780 disclose?
ZDI-23-1780 can disclose sensitive information from affected installations of Adobe Dimension.
Is user interaction required to exploit ZDI-23-1780?
Yes, user interaction is required to exploit ZDI-23-1780 as the target must visit a malicious page or open a malicious file.
Which software is affected by ZDI-23-1780?
ZDI-23-1780 affects installations of Adobe Dimension.