Heap-based Buffer Overflow in Substance3D Designer from Adobe
CVE-2025-21139
7.8HIGH
What is CVE-2025-21139?
Substance3D Designer, developed by Adobe, experiences a Heap-based Buffer Overflow vulnerability in versions 14.0 and earlier. This flaw potentially allows arbitrary code execution within the context of the logged-in user. To exploit this vulnerability, an attacker must induce a user to open a specially crafted malicious file, triggering the overflow and leading to unauthorized actions on the affected system.
Affected Version(s)
Substance3D - Designer 0 <= 14.0