CVE-2025-49569
7.8Adobe · Substance3D - Viewer
Adobe Substance3D Viewer versions 0.25 and earlier contain an out-of-bounds write vulnerability that allows arbitrary code execution via a malicious file.
Executive summary
Adobe Substance3D Viewer versions 0.25 and earlier are vulnerable to arbitrary code execution, requiring urgent attention to prevent potential system compromise.
Vulnerability
This vulnerability is an out-of-bounds write flaw (CWE-787) that allows an attacker to achieve arbitrary code execution in the context of the current user, provided the user is tricked into opening a malicious file.
Business impact
Successful exploitation of this vulnerability permits an attacker to execute arbitrary code with the privileges of the victim, potentially leading to unauthorized data access, system manipulation, or further lateral movement within the network. With a CVSS score of 7.8, this vulnerability represents a significant risk to organizational integrity and confidentiality, particularly in environments where Substance3D Viewer is used to handle external or untrusted files.
Remediation
Immediate Action: Update Adobe Substance3D Viewer to the latest available version provided by the vendor in security bulletin APSB25-72.
Proactive Monitoring: Monitor system logs for unusual process execution patterns or unexpected file access activity initiated by the Substance3D Viewer application.
Compensating Controls: Implement endpoint protection solutions capable of detecting malicious file execution and ensure that users are educated regarding the risks of opening files from untrusted or unknown sources.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the potential for arbitrary code execution, it is imperative that all instances of Adobe Substance3D Viewer are updated to a patched version immediately. Administrators should prioritize this deployment to mitigate the risk of system compromise and ensure that security policies are aligned with vendor recommendations.