ZDI-CAN-22284: ZDI-23-1779: Adobe Dimension GLTF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Dimension. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2023-47062.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-22284?
The severity of ZDI-CAN-22284 is assessed based on the potential for sensitive information disclosure, which can vary with the specific implementation and context.
How do I fix ZDI-CAN-22284?
To fix ZDI-CAN-22284, ensure that you have installed the latest security updates for Adobe Dimension as advised by Adobe.
What type of attacks can ZDI-CAN-22284 facilitate?
ZDI-CAN-22284 can facilitate remote information disclosure attacks if a user interacts with a malicious page or file.
Does ZDI-CAN-22284 require user interaction?
Yes, ZDI-CAN-22284 requires user interaction, such as visiting a malicious page or opening a malicious file, to exploit the vulnerability.
Which software is affected by ZDI-CAN-22284?
ZDI-CAN-22284 specifically affects Adobe Dimension installations.