Heap-based Buffer Overflow in Substance3D Designer by Adobe
CVE-2025-21137
7.8HIGH
What is CVE-2025-21137?
Substance3D Designer versions 14.0 and prior are vulnerable to a Heap-based Buffer Overflow, potentially allowing arbitrary code execution within the context of the user running the application. Successful exploitation requires the user to open a specially crafted file. This vulnerability highlights the importance of exercising caution when handling files from untrusted sources, as it could lead to unauthorized actions on the affected system.
Affected Version(s)
Substance3D - Designer 0 <= 14.0