PT-2025-32900 · Adobe · Substance3D - Modeler
Published
2025-08-12
·
Updated
2025-08-13
·
CVE-2025-49571
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Substance3D - Modeler versions 1.22.0 and earlier
Description:
Substance3D - Modeler is affected by an uncontrolled search path element issue that may lead to arbitrary code execution with current user privileges. An attacker could manipulate the application’s search path to execute a malicious program when the application attempts to locate critical resources. Exploitation of this issue does not require user interaction.
Recommendations:
Update Substance3D - Modeler to a version later than 1.22.0.
Fix
Uncontrolled Search Path Element
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Substance3D - Modeler