Out-of-Bounds Read Vulnerability in Adobe Substance3D Designer Software
CVE-2025-21167

5.5MEDIUM

Key Information:

Vendor

Adobe

Vendor
CVE Published:
8 July 2025

What is CVE-2025-21167?

Adobe Substance3D Designer, specifically versions up to and including 14.1, is affected by a vulnerability that involves out-of-bounds read scenarios. This flaw could allow attackers to disclose sensitive memory data. Exploiting this vulnerability necessitates that a victim interact with a malicious file, which could enable the attacker to effectively bypass various security mitigations such as Address Space Layout Randomization (ASLR). Users of the affected versions should exercise caution and ensure they do not open untrusted files.

Affected Version(s)

Substance3D - Designer 0 <= 14.1

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.