CVE-2025-54243
7.8Adobe · Substance3D - Viewer
Adobe Substance3D Viewer contains an out-of-bounds write vulnerability that allows for arbitrary code execution when a user opens a specially crafted malicious file.
Executive summary
Adobe Substance3D Viewer is vulnerable to an out-of-bounds write flaw that permits arbitrary code execution upon the opening of a malicious file.
Vulnerability
This vulnerability is an out-of-bounds write (CWE-787) occurring within the application, which can be triggered by an attacker if a user is convinced to open a malicious file. The attack requires user interaction and is executed in the context of the currently logged-in user.
Business impact
The ability for an attacker to achieve arbitrary code execution poses a severe risk to organizational security, as it allows for unauthorized system access and potential data theft. Given the CVSS score of 7.8, this vulnerability is classified as High severity and could lead to full compromise of the local workstation if the application is run with elevated privileges.
Remediation
Immediate Action: Update Adobe Substance3D Viewer to the latest available version provided by Adobe as specified in their security advisory.
Proactive Monitoring: Monitor system logs for unusual process execution patterns or crashes associated with the Substance3D Viewer application.
Compensating Controls: Implement strict email filtering and endpoint protection policies to prevent users from opening untrusted or unknown 3D model files from external sources.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Due to the high severity of this remote code execution vulnerability, it is imperative that all affected systems are updated immediately. Security administrators should prioritize identifying installations of Adobe Substance3D Viewer and ensuring the patch is deployed to neutralize the risk of arbitrary code execution.