Out-of-Bounds Write Vulnerability in Substance3D - Stager by Adobe
CVE-2025-21130
7.8HIGH
Summary
Substance3D - Stager by Adobe is impacted by an out-of-bounds write vulnerability in versions 3.0.4 and earlier, which may allow arbitrary code execution within the context of the current user. Successful exploitation requires user interaction, as the victim must open a specially crafted malicious file. This can pose significant security risks, especially in environments where users can be tricked into opening compromised files.
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published