CVE-2025-54258

7.8

Adobe · Substance3D - Modeler

Adobe Substance3D Modeler is vulnerable to a Use After Free flaw that allows for arbitrary code execution when a user opens a malicious file.

Executive summary

Adobe Substance3D Modeler versions 1.22.2 and earlier are susceptible to a critical Use After Free vulnerability that enables arbitrary code execution through malicious file interaction.

Vulnerability

This vulnerability is a Use After Free (CWE-416) condition within the application. It requires a local, unauthenticated user to interact with a specially crafted malicious file to trigger the flaw.

Business impact

The potential impact of this vulnerability is severe, as it facilitates arbitrary code execution within the context of the current user. Given the CVSS score of 7.8, this represents a high risk to organizational security, potentially leading to total system compromise, unauthorized data access, or the deployment of further malicious payloads if a workstation is successfully targeted.

Remediation

Immediate Action: Update Adobe Substance3D Modeler to the latest version provided by the vendor to ensure the Use After Free vulnerability is patched.

Proactive Monitoring: Monitor system logs for unusual application crashes or unexpected execution patterns that may indicate an attempt to trigger memory corruption.

Compensating Controls: Implement strict file validation policies and user awareness training to prevent the opening of untrusted files from unknown sources, which serves as the primary attack vector.

Exploitation status

Public Exploit Available: No (exploit_available: false).

Analyst recommendation

The severity of this vulnerability, combined with its potential for arbitrary code execution, necessitates immediate action. Administrators and end users should verify their current version of Adobe Substance3D Modeler and apply the vendor-supplied update immediately to mitigate the risk of exploitation.

More Adobe CVEs

Sources