Out-of-Bounds Read Vulnerability in Substance3D Stager by Adobe
CVE-2025-54262

7.8HIGH

Key Information:

Vendor

Adobe

Vendor
CVE Published:
16 September 2025

What is CVE-2025-54262?

Adobe Substance3D Stager, specifically versions 3.1.3 and earlier, contains an out-of-bounds read vulnerability. This issue occurs during the processing of specially crafted files, potentially allowing attackers to read beyond the allocated memory limits. If successfully exploited, the vulnerability could enable code execution in the context of the user interacting with the affected application. To be vulnerable, users must open the malicious file, emphasizing the need for caution and awareness when handling unfamiliar files in the application.

Affected Version(s)

Substance3D - Stager 0 <= 3.1.3

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-54262 : Out-of-Bounds Read Vulnerability in Substance3D Stager by Adobe