CVE-2024-20741
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Feb 15, 2024
Updated: Feb 16, 2024
CWE ID 787
CWE ID 123
Summary
CVE-2024-20741 is a newly disclosed vulnerability affecting Substance3D's Painter software versions 9.1.1 and older. This issue represents a Write-what-where Condition vulnerability, which can be exploited to execute arbitrary code in the context of the current user. To leverage the vulnerability, a malicious file must be opened by the victim, making this a user-interactive exploit.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Adobe