ZDI-24-1143: Adobe Dimension SKP File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Dimension. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-34124.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-24-1143?
ZDI-24-1143 has been assigned a CVSS rating indicating a high severity level due to the potential for remote code execution.
How do I fix ZDI-24-1143?
To fix ZDI-24-1143, users should update Adobe Dimension to the latest version provided by Adobe.
Who is affected by ZDI-24-1143?
ZDI-24-1143 affects installations of Adobe Dimension that are exposed to crafted files or malicious web pages.
What is the attack vector for ZDI-24-1143?
The attack vector for ZDI-24-1143 requires user interaction, such as visiting a malicious page or opening a compromised file.
What are the consequences of exploiting ZDI-24-1143?
Exploitation of ZDI-24-1143 could allow remote attackers to execute arbitrary code on the affected system.