VDB

CVE-2023-25876

CVE-2023-25876 PUBLISHED CVSS 5.5 MEDIUM

Adobe Substance 3D Stager versions 2.0.0 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

EPSS 0.22% · 44.7th percentile

Risk Scores

CVSS 3.1
5.5
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS Score
0.22%
44.7th percentile

Affected Products

VendorProductVersions
adobesubstance_3d_stager0
AdobeSubstance3D - Stagerunspecified, unspecified

Timeline

  • Mar 27, 2023 CVE Published
  • Mar 28, 2023 EPSS Score
  • May 5, 2023 EPSS Score
  • Jun 12, 2023 EPSS Score
  • Jul 21, 2023 EPSS Score
  • Aug 28, 2023 EPSS Score
  • Oct 5, 2023 EPSS Score
  • Nov 12, 2023 EPSS Score
  • Dec 21, 2023 EPSS Score
  • Jan 28, 2024 EPSS Score
  • Mar 6, 2024 EPSS Score
  • Apr 13, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›