CVE-2025-61834
7.8Adobe · Substance3D Stager
Adobe Substance3D Stager 3.1.5 and earlier are vulnerable to a Use After Free flaw, which could allow an attacker to achieve arbitrary code execution via a malicious file.
Executive summary
Adobe Substance3D Stager versions 3.1.5 and earlier contain a Use After Free vulnerability that allows for arbitrary code execution when a user opens a specially crafted file.
Vulnerability
The application is susceptible to a Use After Free error (CWE-416) that occurs during the processing of files. An unauthenticated attacker can exploit this by enticing a user to open a malicious file, leading to arbitrary code execution in the context of the current user.
Business impact
The potential for arbitrary code execution poses a severe risk to the confidentiality, integrity, and availability of the host machine. With a CVSS score of 7.8, this high-severity vulnerability could allow an attacker to gain full control over the user session, potentially leading to data exfiltration or the installation of persistent malware within the corporate environment.
Remediation
Immediate Action: Update Adobe Substance3D Stager to the latest available version provided by Adobe in security bulletin APSB25-113.
Proactive Monitoring: Monitor endpoint systems for suspicious child processes spawning from the Substance3D Stager application.
Compensating Controls: Implement organizational policies to restrict the opening of untrusted 3D assets from unknown sources, as user interaction is a required component of the attack chain.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the potential for arbitrary code execution, this vulnerability represents a significant risk to workstations running Adobe Substance3D Stager. Security teams should prioritize patching affected installations immediately to eliminate the threat of malicious file-based exploitation.