CVE-2025-61833
7.8Adobe · Substance3D Stager
Adobe Substance3D Stager 3.1.5 and earlier are vulnerable to an out-of-bounds read that may allow arbitrary code execution when parsing a specially crafted file.
Executive summary
Adobe Substance3D Stager versions 3.1.5 and earlier contain an out-of-bounds read vulnerability that could allow a local attacker to achieve code execution through user interaction.
Vulnerability
The application suffers from an out-of-bounds read (CWE-125) when processing malformed files, which can lead to memory corruption and potential code execution in the context of the current user. Exploitation requires a victim to interact with the software by opening a malicious file.
Business impact
Successful exploitation of this vulnerability could lead to a full compromise of the user's workstation, including unauthorized access to sensitive files and the execution of arbitrary commands. With a CVSS score of 7.8, this flaw represents a significant risk to the confidentiality, integrity, and availability of local systems where Substance3D Stager is installed.
Remediation
Immediate Action: Update Adobe Substance3D Stager to the latest version provided by Adobe in security bulletin APSB25-113.
Proactive Monitoring: Monitor workstation file access logs and endpoint detection systems for unusual process execution patterns triggered by the Substance3D Stager application.
Compensating Controls: Advise users to exercise extreme caution when opening files from untrusted or unknown sources to prevent the accidental execution of malicious content.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the potential for arbitrary code execution, administrators should prioritize patching all instances of Adobe Substance3D Stager. Ensure that users are educated on the risks of opening files from untrusted sources, as the primary attack vector relies on social engineering or the delivery of malicious assets. Applying vendor-supplied updates is the only definitive way to remediate the underlying memory safety flaw.