QID 378393

Date Published: 2023-04-12

QID 378393: Adobe Substance 3D Designer Arbitrary Code Execution Vulnerability (APSB23-28)

Adobe Substance 3D Designer is an application intended for creating 2D textures, materials, filters and 3D models in a node-based interface, with a heavy focus on procedural generation, parametrisation and non-destructive workflows

Affected Versions:
Adobe Substance 3D Designer 12.4.0.0 and prior

QID Detection Logic:(Authenticated)
This QID checks vulnerable versions of Substance 3D Designer.

Successful exploitation could lead to arbitrary code execution

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution

    Adobe has released fix to address this issue. Customers are advised to refer to APSB23-28 for updates pertaining to this vulnerability.

    Software Advisories
    Advisory ID Software Component Link
    APSB23-28 URL Logo helpx.adobe.com/security/products/substance3d_designer/apsb23-28.html