CVE-2025-21164

7.8

Adobe · Substance3D Designer

Adobe Substance3D Designer is susceptible to an out-of-bounds write vulnerability that could allow an attacker to achieve arbitrary code execution via a malicious file.

Executive summary

Adobe Substance3D Designer contains an out-of-bounds write vulnerability that permits arbitrary code execution when a user opens a specially crafted file.

Vulnerability

The software is affected by an out-of-bounds write (CWE-787) flaw. Exploitation requires user interaction, specifically forcing the victim to open a malicious file, which can result in code execution within the context of the current user.

Business impact

Successful exploitation allows an attacker to execute arbitrary code with the privileges of the logged-in user, potentially leading to a complete compromise of the local workstation or environment. Given the high CVSS score of 7.8, this flaw represents a significant risk to organizational assets, as it facilitates unauthorized data access or the installation of persistent malicious software.

Remediation

Immediate Action: Review the official Adobe Security Bulletin APSB25-62 and apply the latest security updates provided by Adobe as soon as they become available.

Proactive Monitoring: Monitor endpoint activity for unusual process execution patterns or unexpected file system modifications initiated by the Substance3D Designer application.

Compensating Controls: Advise users to exercise caution when opening files from untrusted or unknown sources to prevent the triggering of malicious payloads.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

The vulnerability in Adobe Substance3D Designer poses a critical risk to user workstations due to the potential for arbitrary code execution. Organizations should prioritize updating the software to the latest version once the vendor releases a fix and ensure that users are educated on the risks of opening files from unverified origins.

More Adobe CVEs

Sources