CVE-2025-43568: Substance3D - Stager | Use After Free (CWE-416)
Substance3D - Stager versions 3.1.1 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-43568?
CVE-2025-43568 is classified as a critical vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2025-43568?
To mitigate CVE-2025-43568, update to the latest version of Substance3D Stager beyond version 3.1.1.
What types of attacks are possible with CVE-2025-43568?
CVE-2025-43568 could allow attackers to execute arbitrary code on the user's system by tricking them into opening a malicious file.
Does CVE-2025-43568 require user interaction for exploitation?
Yes, exploiting CVE-2025-43568 requires user interaction as the victim must open a malicious file.
Which versions of Substance3D Stager are affected by CVE-2025-43568?
Substance3D Stager versions 3.1.1 and earlier are affected by CVE-2025-43568.