# CVE-2024-47438

## Summary

- **CVE ID:** CVE-2024-47438
- **Severity:** MEDIUM
- **CVSS Score:** 5.5 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)
- **CWE:** CWE-123
- **Published:** Nov 12, 2024
- **Last Modified:** Mar 13, 2026

## Description

Substance3D - Painter versions 10.1.0 and earlier are affected by a Write-what-where Condition vulnerability that could lead to a memory leak. This vulnerability allows an attacker to write a controlled value at a controlled memory location, which could result in the disclosure of sensitive memory content. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

## Affected Products

- Adobe — Substance3D - Painter (0)

## References

- [CNA](https://helpx.adobe.com/security/products/substance3d_painter/apsb24-86.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.23%
- **EPSS Percentile:** 13.3

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-12._