CVE-2025-21165
7.8Adobe · Substance3D - Designer
Adobe Substance3D Designer 14.1 and earlier contain an out-of-bounds write vulnerability that allows for arbitrary code execution when a user opens a specially crafted file.
Executive summary
Adobe Substance3D Designer is affected by a critical out-of-bounds write vulnerability that could allow an attacker to execute arbitrary code on the victim system.
Vulnerability
The application suffers from an out-of-bounds write (CWE-787) flaw. This vulnerability can be triggered by an unauthenticated attacker if they successfully convince a user to open a malicious file within the application.
Business impact
Successful exploitation allows an attacker to execute arbitrary code with the privileges of the currently logged-in user. With a CVSS score of 7.8, this vulnerability poses a high risk to organizational security, as it could lead to full system compromise, data theft, or the installation of persistent malware on workstations used by creative professionals.
Remediation
Immediate Action: Update Adobe Substance3D Designer to the version specified in the vendor security advisory APSB25-62 to resolve this vulnerability.
Proactive Monitoring: Monitor workstation endpoints for unusual process spawning behaviors or unexpected file system modifications initiated by the Substance3D Designer application.
Compensating Controls: Implement strict email and file-download security policies to prevent users from opening untrusted or unsolicited project files from unknown sources.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the potential for arbitrary code execution, this vulnerability should be prioritized for patching across all systems running Adobe Substance3D Designer. Security teams should ensure that all users are updated to a secure version and remain vigilant regarding the opening of untrusted files.