CVE-2025-54259
7.8Adobe · Substance3D Modeler
Adobe Substance3D Modeler is vulnerable to an integer overflow that can lead to arbitrary code execution when a user opens a specially crafted file.
Executive summary
Adobe Substance3D Modeler versions 1.22.2 and earlier contain an integer overflow vulnerability that allows for arbitrary code execution upon opening a malicious file.
Vulnerability
This is an integer overflow or wraparound flaw (CWE-190) that occurs when processing malformed files. The vulnerability requires user interaction, as a victim must open a malicious file to trigger the execution context of the current user.
Business impact
The ability for an attacker to achieve arbitrary code execution poses a severe risk to organizational security, potentially leading to a full system compromise. With a CVSS score of 7.8, this vulnerability is classified as High, as it allows attackers to gain the same privileges as the logged-in user, which could result in data theft, malware installation, or unauthorized lateral movement within the network.
Remediation
Immediate Action: Review the Adobe security bulletin APSB25-92 to identify the specific patched version and apply the update to all installations immediately.
Proactive Monitoring: Monitor endpoint processes for unusual child processes spawned by Substance3D Modeler and review file access logs for suspicious file imports.
Compensating Controls: Implement file integrity monitoring and ensure that users are advised against opening untrusted 3D model files from unknown or unverified sources.
Exploitation status
Public Exploit Available: Unknown (exploit_available: false)
Analyst recommendation
Given the potential for arbitrary code execution, this vulnerability represents a significant security risk to any workstation running the affected software. Administrators should prioritize identifying all instances of Adobe Substance3D Modeler and verify their patch status against the vendor advisory. Apply the vendor update as soon as it becomes available to eliminate the attack surface created by this integer overflow.