CVE-2025-54244
7.8Adobe · Substance3D - Viewer
Adobe Substance3D Viewer contains a heap-based buffer overflow vulnerability that allows an attacker to achieve arbitrary code execution through the opening of a malicious file.
Executive summary
Adobe Substance3D Viewer is vulnerable to a heap-based buffer overflow that could allow an attacker to execute arbitrary code on the victim's system via a malicious file.
Vulnerability
This is a heap-based buffer overflow (CWE-122) occurring within the Substance3D Viewer application. The vulnerability requires user interaction, as a victim must open a specially crafted malicious file to trigger the flaw.
Business impact
The ability for an unauthenticated attacker to achieve arbitrary code execution presents a high risk to organizational security, as indicated by the CVSS score of 7.8. Successful exploitation could lead to full system compromise, unauthorized data access, and the potential for lateral movement within the network. Because the attack vector is local and requires user interaction, the primary risk involves the compromise of individual workstations or creative production environments.
Remediation
Immediate Action: Update Adobe Substance3D Viewer to the version specified in the vendor advisory (APSB25-89) to eliminate the vulnerable code path.
Proactive Monitoring: Monitor endpoint logs for abnormal application crashes or unexpected child processes spawned by the Substance3D Viewer executable.
Compensating Controls: Implement strict email and file-download filtering policies to prevent users from opening untrusted or unsolicited 3D model files from unknown sources.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for arbitrary code execution, this vulnerability should be treated as a high-priority remediation item. Organizations should identify all systems running the affected versions of Adobe Substance3D Viewer and apply the vendor-supplied security update immediately. Until patching is complete, users should be cautioned against opening files originating from unverified or untrusted sources.