CVE-2025-54245
7.8Adobe · Substance3D - Viewer
Adobe Substance3D Viewer contains an out-of-bounds write vulnerability that allows for arbitrary code execution when a user opens a specially crafted malicious file.
Executive summary
Adobe Substance3D Viewer is vulnerable to an out-of-bounds write flaw that could allow a remote attacker to achieve arbitrary code execution on a victim's system.
Vulnerability
The software suffers from an out-of-bounds write (CWE-787) that occurs when processing files. Exploitation requires user interaction, specifically the opening of a malicious file by an authenticated or unauthenticated user within the context of the current session.
Business impact
The ability to execute arbitrary code provides an attacker with full control over the affected workstation, potentially leading to the theft of sensitive data, installation of malware, or lateral movement within the corporate network. With a CVSS score of 7.8, this vulnerability represents a high risk to organizational security, particularly for creative teams that regularly process external 3D assets.
Remediation
Immediate Action: Update Adobe Substance3D Viewer to the latest patched version available via the Adobe Creative Cloud desktop application or the official vendor support portal.
Proactive Monitoring: Monitor endpoint detection logs for unusual process spawning from the Substance3D Viewer application.
Compensating Controls: Implement strict file validation policies and ensure that users are trained to exercise caution when opening 3D files from untrusted or unknown sources.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the high CVSS score and the potential for complete system compromise, organizations should prioritize updating all instances of Adobe Substance3D Viewer. IT administrators must ensure that the patch is deployed across all workstations to neutralize the risk of arbitrary code execution stemming from malicious file processing.