Uncontrolled Search Path Element Flaw in Substance3D Modeler by Adobe
CVE-2025-49571

7.8HIGH

Key Information:

Vendor

Adobe

Vendor
CVE Published:
12 August 2025

What is CVE-2025-49571?

Substance3D Modeler versions 1.22.0 and earlier are susceptible to an uncontrolled search path element vulnerability. This flaw allows attackers to manipulate the search paths utilized by the application to locate essential resources. By redirecting these paths, an attacker can execute arbitrary code with the privileges of the current user, leading to potentially severe security risks. Remarkably, successful exploitation does not necessitate any interaction from the user, emphasizing the critical nature of this vulnerability.

Affected Version(s)

Substance3D - Modeler 0 <= 1.22.0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.