Access of Uninitialized Pointer in Substance 3D Stager - CVE-2023-26387

 

Access of Uninitialized Pointer in Substance 3D Stager - CVE-2023-26387

Published: April 11, 2023 / Updated: April 13, 2023


Vulnerability identifier: #VU74945
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-26387
CWE-ID: CWE-824
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to a boundary condition. A remote attacker can create a specially crafted file, trick the victim into opening it, trigger memory corruption and gain access to contents of memory on the system.


Affected software

Substance 3D Stager

How to mitigate CVE-2023-26387

Install updates from vendor's website.

Substance 3D Stager - update to 2.0.2

External References

Related Security Bulletins