CVE-2025-54243

7.8

Adobe · Substance3D - Viewer

Adobe Substance3D Viewer contains an out-of-bounds write vulnerability that allows for arbitrary code execution when a user opens a specially crafted malicious file.

Executive summary

Adobe Substance3D Viewer is vulnerable to an out-of-bounds write flaw that permits arbitrary code execution upon the opening of a malicious file.

Vulnerability

This vulnerability is an out-of-bounds write (CWE-787) occurring within the application, which can be triggered by an attacker if a user is convinced to open a malicious file. The attack requires user interaction and is executed in the context of the currently logged-in user.

Business impact

The ability for an attacker to achieve arbitrary code execution poses a severe risk to organizational security, as it allows for unauthorized system access and potential data theft. Given the CVSS score of 7.8, this vulnerability is classified as High severity and could lead to full compromise of the local workstation if the application is run with elevated privileges.

Remediation

Immediate Action: Update Adobe Substance3D Viewer to the latest available version provided by Adobe as specified in their security advisory.

Proactive Monitoring: Monitor system logs for unusual process execution patterns or crashes associated with the Substance3D Viewer application.

Compensating Controls: Implement strict email filtering and endpoint protection policies to prevent users from opening untrusted or unknown 3D model files from external sources.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Due to the high severity of this remote code execution vulnerability, it is imperative that all affected systems are updated immediately. Security administrators should prioritize identifying installations of Adobe Substance3D Viewer and ensuring the patch is deployed to neutralize the risk of arbitrary code execution.

More Adobe CVEs

Sources