CVE-2025-21166
7.8Adobe · Substance3D Designer
Adobe Substance3D Designer 14.1 and earlier contains an out-of-bounds write vulnerability that could allow an attacker to achieve arbitrary code execution via a malicious file.
Executive summary
Adobe Substance3D Designer is affected by a critical out-of-bounds write vulnerability that enables arbitrary code execution when a user opens a specially crafted file.
Vulnerability
This is an out-of-bounds write flaw (CWE-787) that occurs when processing malformed files. Successful exploitation requires user interaction, specifically that a victim opens a malicious file provided by an attacker.
Business impact
The ability for an attacker to execute arbitrary code in the context of the current user poses a significant security risk to workstation integrity. Successful exploitation could lead to full system compromise, data theft, or the installation of persistent malicious software. With a CVSS score of 7.8, this vulnerability represents a high-severity risk that requires immediate attention to prevent potential lateral movement within the corporate network.
Remediation
Immediate Action: Update Adobe Substance3D Designer to the version specified in the vendor security advisory at https://helpx.adobe.com/security/products/substance3d_designer/apsb25-62.html.
Proactive Monitoring: Monitor endpoint activity for unusual spawned processes originating from the Substance3D Designer application. Review system logs for unexpected file access patterns or application crashes.
Compensating Controls: Implement file integrity monitoring and ensure that users are trained to exercise caution when opening files from untrusted or unknown sources. Utilize endpoint detection and response tools to identify and block suspicious file execution attempts.
Exploitation status
Public Exploit Available: No (exploit_available: false).
Analyst recommendation
Given the potential for arbitrary code execution, it is imperative that all installations of Adobe Substance3D Designer are updated to the latest patched version immediately. Organizations should prioritize patching on systems used by design professionals who frequently interact with external or untrusted assets. Until updates are applied, restrict the opening of files from non-reputable sources to minimize the attack surface.