Adobe Substance 3D Stager Let Attacker Execute Arbitrary Code

Adobe has released a security update that fixes “Important-severity” vulnerabilities in its Substance 3D Stager product. The successful exploitation of these issues could result in a memory leak and arbitrary code execution in the current user’s context.

Adobe Substance 3D Stager is a cutting-edge staging tool for creating 3D scenes using real-time 3D visualization and high-quality renderings.

At the time of release, none of the flaws that Adobe patched this month were known to the public or targeted by active attacks. These upgrades have a deployment priority rating of 3, according to Adobe. 

Document
Free Webinar

Fastrack Compliance: The Path to ZERO-Vulnerability

Compounding the problem are zero-day vulnerabilities like the MOVEit SQLi, Zimbra XSS, and 300+ such vulnerabilities that get discovered each month. Delays in fixing these vulnerabilities lead to compliance issues, these delay can be minimized with a unique feature on AppTrana that helps you to get “Zero vulnerability report” within 72 hours.

Vulnerabilities Addressed

Six security vulnerabilities in Adobe’s Substance 3D Stager product have been patched, such as:

The Out-of-bounds Read categories CVE-2024-20710, CVE-2024-20711, CVE-2024-20712, CVE-2024-20714, and CVE-2024-20715 have a severity rating of “Important” with a CVSS base score of 5.5.

These vulnerabilities enable a remote attacker to obtain access to potentially sensitive information.

The vulnerability exists because of a boundary condition. A remote attacker can generate a specially crafted file, mislead the victim into opening it, cause an out-of-bounds read error, and read memory from the system.

The CVE-2024-20713 with Improper Input Validation category has a CVSS base score of 5.5, allowing a remote attacker to access the compromised machine.

The insufficient validation of user-supplied input is the cause of the vulnerability. A remote attacker can take control of the system and run arbitrary code by tricking the user into opening a maliciously created file.

Vulnerability CategoryVulnerability ImpactSeverityCVSS base score CVE Numbers
Out-of-bounds Read (CWE-125)Memory leakImportant5.5CVE-2024-20710
Out-of-bounds Read (CWE-125)Memory leakImportant5.5CVE-2024-20711
Out-of-bounds Read (CWE-125)Memory leakImportant5.5CVE-2024-20712
Improper Input Validation (CWE-20)Arbitrary code executionImportant5.5CVE-2024-20713
Out-of-bounds Read (CWE-125)Memory leakImportant5.5CVE-2024-20714
Out-of-bounds Read (CWE-125)Memory leakImportant5.5CVE-2024-20715

Affected Versions

Adobe Substance 3D Stager 2.1.3 and earlier versions

Platforms: Windows and macOS

Update Now

Upgrade to the Substance 3D Stager version 2.1.4

“Adobe categorizes these updates with the following priority ratings and recommends users update their installation to the newest version via the Creative Cloud desktop app’s update mechanism,” the company said.

Gurubaran

Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Recent Posts

“Password Era is Ending,” Microsoft to Delete 1 Billion Passwords

Microsoft has announced that it is currently blocking an astounding 7,000 password attacks every second,…

2 days ago

Over 300,000 Prometheus Servers Vulnerable to DoS Attacks Due to RepoJacking Exploit

The research identified vulnerabilities in Prometheus, including information disclosure from exposed servers, DoS risks from…

2 days ago

Reyee OS IoT Devices Compromised: Over-The-Air Attack Bypasses Wi-Fi Logins

Researchers discovered multiple vulnerabilities in Ruijie Networks' cloud-connected devices. By exploiting these vulnerabilities, attackers can…

2 days ago

New Android Banking Malware Attacking Indian Banks To Steal Login Credentials

Researchers have discovered a new Android banking trojan targeting Indian users, and this malware disguises…

2 days ago

New Research Uncovered Dark Internet Service Providers Used For Hacking

Bulletproof hosting services, a type of dark internet service provider, offer infrastructure to cybercriminals, facilitating…

2 days ago

Nigerian National Extradited to Nebraska for Wire Fraud Charges

United States Attorney Susan Lehr announced the extradition of Abiola Kayode, 37, from Nigeria to…

3 days ago