CVE-2023-26387
Published: 12 April 2023
Summary
CVE-2023-26387 is a medium-severity Access of Uninitialized Pointer (CWE-824) vulnerability in Adobe Substance 3D Stager. Its CVSS base score is 5.5 (Medium).
Operationally, ranked at the 38.7th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2023-30207
Vulnerability details
Adobe Substance 3D Stager version 2.0.1 (and earlier) is affected by an Access of Uninitialized Pointer vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this…
more
issue requires user interaction in that a victim must open a malicious file.
- CWE(s)
Related Threats
No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.
Affected Assets
Mitigating Controls
No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.