CVE-2025-54195
📋 TL;DR
Substance3D Painter versions 11.0.2 and earlier contain an out-of-bounds read vulnerability that could allow attackers to read sensitive memory contents. This affects users who open malicious project files in the software. The vulnerability requires user interaction to exploit.
💻 Affected Systems
- Adobe Substance3D Painter
📦 What is this software?
⚠️ Risk & Real-World Impact
Worst Case
An attacker could exfiltrate sensitive data from memory, potentially including credentials, encryption keys, or other application secrets.
Likely Case
Limited information disclosure from application memory, possibly revealing file paths, temporary data, or partial memory contents.
If Mitigated
With proper controls, impact is minimal as exploitation requires user interaction and malicious file execution.
🎯 Exploit Status
Exploitation requires crafting a malicious project file and convincing a user to open it. No public exploit code is known.
🛠️ Fix & Mitigation
✅ Official Fix
Patch Version: 11.0.3 or later
Vendor Advisory: https://helpx.adobe.com/security/products/substance3d_painter/apsb25-77.html
Restart Required: No
Instructions:
1. Open Substance3D Painter. 2. Go to Help > Check for Updates. 3. Follow prompts to install version 11.0.3 or later. 4. Alternatively, download the latest version from Adobe's website.
🔧 Temporary Workarounds
Restrict file opening
allOnly open project files from trusted sources and verify file integrity before opening.
🧯 If You Can't Patch
- Implement application whitelisting to prevent execution of unauthorized files
- Educate users about the risks of opening untrusted project files
🔍 How to Verify
Check if Vulnerable:
Check Help > About Substance3D Painter. If version is 11.0.2 or earlier, the system is vulnerable.
Check Version:
Not applicable - check via application GUI
Verify Fix Applied:
Verify version is 11.0.3 or later in Help > About Substance3D Painter.
📡 Detection & Monitoring
Log Indicators:
- Application crashes when opening project files
- Unusual memory access patterns in application logs
Network Indicators:
- Unexpected outbound connections after opening project files
SIEM Query:
EventID for application crashes related to Substance3D Painter or suspicious file access patterns