CVE-2025-49560

7.8

Adobe · Substance3D Viewer

Adobe Substance3D Viewer versions 0.25 and earlier are vulnerable to a heap-based buffer overflow that can lead to arbitrary code execution if a user opens a malicious file.

Executive summary

Adobe Substance3D Viewer is susceptible to a heap-based buffer overflow vulnerability that allows for arbitrary code execution when a user opens a specially crafted file.

Vulnerability

The application contains a heap-based buffer overflow (CWE-122) triggered when a user opens a malicious file. This vulnerability allows an attacker to achieve arbitrary code execution in the context of the current user, requiring successful user interaction.

Business impact

A successful exploitation of this vulnerability could lead to a complete compromise of the user workstation, resulting in unauthorized data access, potential lateral movement within the network, and loss of system integrity. With a CVSS score of 7.8, this vulnerability is categorized as High severity, reflecting the significant risk posed by the potential for arbitrary code execution.

Remediation

Immediate Action: Update Adobe Substance3D Viewer to the version specified in the vendor security advisory (APSB25-72) to remediate the buffer overflow flaw.

Proactive Monitoring: Review endpoint security logs for unusual process execution patterns or crashes associated with the Substance3D Viewer application.

Compensating Controls: Utilize endpoint protection solutions to scan files before opening and restrict the execution of applications from untrusted sources.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the potential for arbitrary code execution, this vulnerability poses a significant risk to organizational endpoints. Administrators should verify their current version of Adobe Substance3D Viewer and apply the relevant security patches provided by Adobe immediately to prevent potential exploitation.

More Adobe CVEs

Sources