CVE-2025-49560
7.8Adobe · Substance3D Viewer
Adobe Substance3D Viewer versions 0.25 and earlier are vulnerable to a heap-based buffer overflow that can lead to arbitrary code execution if a user opens a malicious file.
Executive summary
Adobe Substance3D Viewer is susceptible to a heap-based buffer overflow vulnerability that allows for arbitrary code execution when a user opens a specially crafted file.
Vulnerability
The application contains a heap-based buffer overflow (CWE-122) triggered when a user opens a malicious file. This vulnerability allows an attacker to achieve arbitrary code execution in the context of the current user, requiring successful user interaction.
Business impact
A successful exploitation of this vulnerability could lead to a complete compromise of the user workstation, resulting in unauthorized data access, potential lateral movement within the network, and loss of system integrity. With a CVSS score of 7.8, this vulnerability is categorized as High severity, reflecting the significant risk posed by the potential for arbitrary code execution.
Remediation
Immediate Action: Update Adobe Substance3D Viewer to the version specified in the vendor security advisory (APSB25-72) to remediate the buffer overflow flaw.
Proactive Monitoring: Review endpoint security logs for unusual process execution patterns or crashes associated with the Substance3D Viewer application.
Compensating Controls: Utilize endpoint protection solutions to scan files before opening and restrict the execution of applications from untrusted sources.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the potential for arbitrary code execution, this vulnerability poses a significant risk to organizational endpoints. Administrators should verify their current version of Adobe Substance3D Viewer and apply the relevant security patches provided by Adobe immediately to prevent potential exploitation.