CVSS 3.1 Score 7.8 of 10 (high)


Published Feb 15, 2024
Updated: Feb 16, 2024
CWE ID 125


CVE-2024-20742 is an out-of-bounds read vulnerability affecting Substance3D - Painter versions 9.1.1 and earlier. This vulnerability occurs when parsing a crafted file, potentially leading to a read beyond the allocated memory structure. Exploiting this vulnerability requires user interaction, as the victim needs to open a malicious file. An attacker could leverage this vulnerability to execute code in the context of the current user. The affected products include various versions of Substance3D - Painter. To remediate this issue, users should update to a version later than 9.1.1. This vulnerability poses a high risk to organizations, with a base severity score of 7.8 and potential impacts on confidentiality, integrity, and availability of the affected systems or data.

Explore Beyond the CVE Basics with Recorded Future's Vulnerability Intelligence

Note: This is just a basic overview providing quick insights into CVE-2024-20742 information. Gain full access to comprehensive CVE data, risk scores, prioritization, and mitigation data through Recorded Future's Vulnerability Intelligence:
  • Prioritize with Risk-Based Scoring
  • Explore the Extensive Vulnerability Database
  • Receive Early Alerts on Emerging CVEs
  • Focus on Critical Exploitable Vulnerabilities
  • Streamline Remediation with Integration Options