CVE-2025-43570: Substance3D - Stager | Use After Free (CWE-416)
Substance3D - Stager versions 3.1.1 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-43570?
The severity of CVE-2025-43570 is considered critical due to its potential for arbitrary code execution.
How do I fix CVE-2025-43570?
To fix CVE-2025-43570, users should upgrade to a patched version of Substance3D Stager later than 3.1.1.
What causes the vulnerability CVE-2025-43570?
CVE-2025-43570 is caused by a Use After Free vulnerability that can be triggered when opening a specially crafted malicious file.
Can CVE-2025-43570 be exploited without user interaction?
No, exploitation of CVE-2025-43570 requires user interaction, specifically requiring the victim to open a malicious file.
Which versions of Substance3D Stager are affected by CVE-2025-43570?
CVE-2025-43570 affects Substance3D Stager versions 3.1.1 and earlier.