Substance3D - Stager versions 3.0.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Metrics
Affected Vendors & Products
References
History
Wed, 12 Feb 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 17 Jan 2025 21:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Adobe
Adobe substance 3d Stager Apple Apple macos Microsoft Microsoft windows |
|
CPEs | cpe:2.3:a:adobe:substance_3d_stager:*:*:*:*:*:*:*:* cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
|
Vendors & Products |
Adobe
Adobe substance 3d Stager Apple Apple macos Microsoft Microsoft windows |
Tue, 14 Jan 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Substance3D - Stager versions 3.0.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
Title | Substance3D - Stager | Out-of-bounds Write (CWE-787) | |
Weaknesses | CWE-787 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: adobe
Published: 2025-01-14T18:58:31.065Z
Updated: 2025-02-12T20:31:18.869Z
Reserved: 2024-12-04T17:19:21.473Z
Link: CVE-2025-21131

Updated: 2025-02-12T20:25:16.567Z

Status : Analyzed
Published: 2025-01-14T19:15:33.897
Modified: 2025-01-17T20:37:30.750
Link: CVE-2025-21131

No data.