CVE-2025-54262
7.8Adobe · Substance3D Stager
Adobe Substance3D Stager is vulnerable to an out-of-bounds read that may allow a local attacker to achieve code execution via a maliciously crafted file requiring user interaction.
Executive summary
Adobe Substance3D Stager versions 3.1.3 and earlier are susceptible to an out-of-bounds read vulnerability that could allow for arbitrary code execution when a victim opens a crafted file.
Vulnerability
The application suffers from an out-of-bounds read (CWE-125) triggered during the parsing of malformed files. This vulnerability requires user interaction to execute, but if successful, it allows for code execution in the context of the current user.
Business impact
Successful exploitation of this flaw poses a significant risk to workstations, as it allows attackers to execute arbitrary code with the privileges of the logged-in user. With a CVSS score of 7.8, this vulnerability is classified as High severity, indicating that it could lead to full system compromise, data theft, or the installation of persistent malicious software.
Remediation
Immediate Action: Review the Adobe security advisory APSB25-81 and apply the latest security updates provided by the vendor as soon as they become available.
Proactive Monitoring: Monitor workstation endpoint logs for unusual application behavior, such as unexpected crashes or unauthorized processes spawning from the Substance3D Stager executable.
Compensating Controls: Advise users to exercise caution when opening files from untrusted sources, as the attack vector requires the manual opening of a malicious file.
Exploitation status
Public Exploit Available: No (exploit_available: unknown)
Analyst recommendation
Given the High severity rating and the potential for code execution, organizations should prioritize the deployment of the forthcoming vendor patch. Until an update is available, users should be instructed to avoid opening Substance3D files from untrusted or unknown origins to minimize the risk of triggering this vulnerability.