Heap-based Buffer Overflow in Substance3D Designer by Adobe
CVE-2025-21137
7.8HIGH
Summary
Substance3D Designer versions 14.0 and prior are vulnerable to a Heap-based Buffer Overflow, potentially allowing arbitrary code execution within the context of the user running the application. Successful exploitation requires the user to open a specially crafted file. This vulnerability highlights the importance of exercising caution when handling files from untrusted sources, as it could lead to unauthorized actions on the affected system.
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published