VDB
CVE-2023-25876
CVE-2023-25876
PUBLISHED
CVSS 5.5 MEDIUM
Adobe Substance 3D Stager versions 2.0.0 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
EPSS 0.22% · 44.7th percentile
Risk Scores
CVSS 3.1
5.5
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS Score
0.22%
44.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| adobe | substance_3d_stager | 0 |
| Adobe | Substance3D - Stager | unspecified, unspecified |
Exploit Intelligence
Timeline
- Mar 27, 2023 CVE Published
- Mar 28, 2023 EPSS Score
- May 5, 2023 EPSS Score
- Jun 12, 2023 EPSS Score
- Jul 21, 2023 EPSS Score
- Aug 28, 2023 EPSS Score
- Oct 5, 2023 EPSS Score
- Nov 12, 2023 EPSS Score
- Dec 21, 2023 EPSS Score
- Jan 28, 2024 EPSS Score
- Mar 6, 2024 EPSS Score
- Apr 13, 2024 EPSS Score