CVE-2025-64531

7.8

Adobe · Substance3D Stager

Adobe Substance3D Stager 3.1.5 and earlier are vulnerable to a Use After Free flaw that allows arbitrary code execution via a malicious file.

Executive summary

Adobe Substance3D Stager contains a critical Use After Free vulnerability that may allow an attacker to achieve arbitrary code execution on a victim system.

Vulnerability

The software is susceptible to a Use After Free vulnerability, documented as CWE-416, which can be triggered when a user opens a specially crafted malicious file. This attack vector requires user interaction and occurs in the context of the current logged-in user.

Business impact

Successful exploitation of this vulnerability allows an attacker to execute arbitrary code with the privileges of the user running the application. Given the CVSS score of 7.8, this represents a high-severity risk that could lead to full system compromise, unauthorized data access, or the deployment of additional malicious payloads within the corporate environment.

Remediation

Immediate Action: Review the official Adobe security bulletin APSB25-113 to determine if a patch is available for your specific environment and apply all recommended software updates immediately.

Proactive Monitoring: Monitor endpoint activity for suspicious file handling processes or unexpected application crashes within Substance3D Stager that may indicate an exploitation attempt.

Compensating Controls: Ensure that users are educated on the risks of opening files from untrusted sources and maintain endpoint protection solutions that can detect malicious file-based execution patterns.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The severity of this flaw necessitates prompt attention from IT security teams. Organizations should prioritize updating all instances of Adobe Substance3D Stager to the latest secure version once confirmed by the vendor, while concurrently restricting the ability of users to open files from unverified or untrusted locations.

More Adobe CVEs

Sources