CVE-2024-20741

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Feb 15, 2024
Updated: Feb 16, 2024
CWE ID 787
CWE ID 123

Summary

CVE-2024-20741 is a newly disclosed vulnerability affecting Substance3D's Painter software versions 9.1.1 and older. This issue represents a Write-what-where Condition vulnerability, which can be exploited to execute arbitrary code in the context of the current user. To leverage the vulnerability, a malicious file must be opened by the victim, making this a user-interactive exploit.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share