Out-of-Bounds Write Vulnerability in Substance3D - Stager by Adobe
CVE-2025-21130

7.8HIGH

Key Information:

Vendor
Adobe
Vendor
CVE Published:
14 January 2025

Summary

Substance3D - Stager by Adobe is impacted by an out-of-bounds write vulnerability in versions 3.0.4 and earlier, which may allow arbitrary code execution within the context of the current user. Successful exploitation requires user interaction, as the victim must open a specially crafted malicious file. This can pose significant security risks, especially in environments where users can be tricked into opening compromised files.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.