Out-of-Bounds Read Vulnerability in Substance3D Painter by Adobe
CVE-2025-54189

5.5MEDIUM

Key Information:

Vendor

Adobe

Vendor
CVE Published:
12 August 2025

What is CVE-2025-54189?

An out-of-bounds read vulnerability exists in Adobe Substance3D Painter versions 11.0.2 and earlier, potentially allowing an attacker to access sensitive information from memory. Successful exploitation requires user interaction, as the user must open a specially crafted file. This issue underscores the importance of keeping software updated and being cautious with file sources.

Affected Version(s)

Substance3D - Painter 0 <= 11.0.2

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-54189 : Out-of-Bounds Read Vulnerability in Substance3D Painter by Adobe