Out-of-Bounds Read Vulnerability in Adobe Substance3D Stager
CVE-2025-43551

5.5MEDIUM

Key Information:

Vendor

Adobe

Vendor
CVE Published:
13 May 2025

What is CVE-2025-43551?

The Adobe Substance3D Stager application, specifically versions 3.1.1 and earlier, is susceptible to an out-of-bounds read vulnerability. This flaw may allow attackers to obtain sensitive information from memory by exploiting the software's handling of certain files. The exploitation requires that a user interact with a malicious file, which could lead to the bypassing of security measures like Address Space Layout Randomization (ASLR). Users are advised to exercise caution when opening files from unknown or untrusted sources.

Affected Version(s)

Substance3D - Stager 0 <= 3.1.1

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-43551 : Out-of-Bounds Read Vulnerability in Adobe Substance3D Stager