CVE-2025-54260
7.8Adobe · Substance3D Modeler
Adobe Substance3D Modeler is affected by an out-of-bounds read vulnerability that may allow an attacker to execute arbitrary code via a malicious file.
Executive summary
Adobe Substance3D Modeler versions 1.22.2 and earlier contain an out-of-bounds read flaw that could lead to arbitrary code execution if a user opens a specially crafted file.
Vulnerability
This is an out-of-bounds read vulnerability (CWE-125) triggered when the application parses a malicious file. The flaw allows an unauthenticated attacker to achieve code execution in the context of the current user, provided the user is enticed to open the crafted file.
Business impact
The potential for arbitrary code execution poses a severe risk to organizational assets, as it could allow an attacker to gain full control over the victim's workstation. With a CVSS score of 7.8, this vulnerability is classified as High, reflecting the significant threat to system confidentiality, integrity, and availability. Successful exploitation could lead to data theft, installation of persistent backdoors, or lateral movement within the corporate network.
Remediation
Immediate Action: Update Adobe Substance3D Modeler to the latest version as specified in the Adobe security bulletin APSB25-92.
Proactive Monitoring: Monitor endpoint logs for abnormal application crashes or unauthorized process executions originating from the Substance3D Modeler process.
Compensating Controls: Implement strict email filtering and web gateway policies to block suspicious file types and prevent users from opening untrusted model files.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for complete system compromise via remote code execution, administrators should prioritize updating all instances of Adobe Substance3D Modeler to a version beyond 1.22.2. Users should be cautioned against opening files from untrusted or unknown sources until the software has been successfully patched.