Out-of-Bounds Read Vulnerability in Substance3D Designer by Adobe
CVE-2025-21168

5.5MEDIUM

Key Information:

Vendor

Adobe

Vendor
CVE Published:
8 July 2025

What is CVE-2025-21168?

An out-of-bounds read vulnerability exists in versions 14.1 and earlier of Substance3D Designer by Adobe. This security flaw could allow attackers to disclose sensitive memory information. Exploitation requires user interaction, as it necessitates the opening of a specially crafted malicious file. If successful, an attacker may bypass security mitigations like Address Space Layout Randomization (ASLR), potentially leading to further exploitation. It is advised that users remain vigilant and apply necessary security patches to minimize risks.

Affected Version(s)

Substance3D - Designer 0 <= 14.1

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.