CVE-2025-61835

7.8

Adobe · Substance3D Stager

Adobe Substance3D Stager 3.1.5 and earlier are vulnerable to an integer underflow flaw, potentially allowing arbitrary code execution when a victim opens a specially crafted malicious file.

Executive summary

Adobe Substance3D Stager versions 3.1.5 and earlier contain an integer underflow vulnerability that could lead to arbitrary code execution if a user opens a malicious file.

Vulnerability

This vulnerability is an integer underflow (CWE-191) that occurs when processing malformed files. Successful exploitation requires user interaction, as a victim must be tricked into opening a malicious file, at which point the attacker can execute code in the context of the current user.

Business impact

The ability for an attacker to achieve arbitrary code execution poses a severe risk to the confidentiality, integrity, and availability of the host system. With a CVSS score of 7.8, this high-severity vulnerability could allow an attacker to gain full control over the user session, potentially leading to data exfiltration or the installation of persistent malware.

Remediation

Immediate Action: Update Adobe Substance3D Stager to the latest available version as specified in the vendor security advisory APSB25-113.

Proactive Monitoring: Monitor for unusual application behavior or crashes occurring when users open third-party files, and review system logs for suspicious process spawning.

Compensating Controls: Implement endpoint protection solutions that scan incoming files for malicious patterns and enforce the principle of least privilege to restrict the impact of potential code execution.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the potential for arbitrary code execution, this vulnerability represents a significant security risk. Administrators should prioritize updating all instances of Adobe Substance3D Stager to the patched version provided by the vendor to prevent potential exploitation.

More Adobe CVEs

Sources