Rewterz
Rewterz Threat Advisory – Multiple GitLab Community Edition and Enterprise Edition Vulnerabilities
January 16, 2024
Rewterz
Rewterz Threat Alert – STOP aka DJVU Ransomware – Active IOCs
January 16, 2024

Rewterz Threat Advisory – Multiple Adobe Substance 3D Stager Vulnerabilities

Severity

Medium

Analysis Summary

CVE-2024-20710 CVSS:5.5

Adobe Substance 3D Stager could allow a remote attacker to obtain sensitive information, caused by an out-of-bounds read. By persuading a victim to open a specially crafted document, a remote attacker could exploit this vulnerability to obtain sensitive information.

CVE-2024-20713 CVSS:5.5

Adobe Substance 3D Stager could allow a remote attacker to execute arbitrary code on the system, caused by improper input validation. By persuading a victim to open a specially crafted document, a remote attacker could exploit this vulnerability to execute arbitrary code on the system.

CVE-2024-20711, CVE-2024-20712

Adobe Substance 3D Stager could allow a remote attacker to obtain sensitive information, caused by an out-of-bounds read. By persuading a victim to open a specially crafted document, a remote attacker could exploit this vulnerability to obtain sensitive information.

CVE-2024-20714, CVE-2024-20715

Adobe Substance 3D Stager could allow a remote attacker to obtain sensitive information, caused by an out-of-bounds read. By persuading a victim to open a specially crafted document, a remote attacker could exploit this vulnerability to obtain sensitive information.

Impact

  • Information Disclosure
  • Code Execution

Indicators Of Compromise

CVE

  • CVE-2024-20710
  • CVE-2024-20713
  • CVE-2024-20711
  • CVE-2024-20712
  • CVE-2024-20714
  • CVE-2024-20715

Affected Vendors

Adobe

Affected Products

  • Adobe Substance 3D Stager 2.1.3

Remediation

Refer to Adobe Security Advisory for patch, upgrade or suggested workaround information.

Adobe Security Advisory