CVE-2025-43582: Substance3D - Viewer | Heap-based Buffer Overflow (CWE-122)
Published Jul 8, 2025
·Updated
Substance3D - Viewer versions 0.22 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user, scope unchanged. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
2 affected components
Substance3D Viewer<0.22
Adobe Substance 3d Viewer<0.25
Event History
Jul 8, 2025
CVE Published
via MITRE·09:07 PM
Data Sourced
via MITRE·09:07 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-43582?
CVE-2025-43582 is classified as a high severity vulnerability due to its potential for arbitrary code execution.
2
How do I fix CVE-2025-43582?
To mitigate CVE-2025-43582, update Substance3D Viewer to version 0.23 or later.
3
What type of vulnerability is CVE-2025-43582?
CVE-2025-43582 is a heap-based buffer overflow vulnerability.
4
What are the consequences of exploiting CVE-2025-43582?
Exploiting CVE-2025-43582 could allow an attacker to execute arbitrary code on the affected system.
5
Who is affected by CVE-2025-43582?
Users running Substance3D Viewer versions 0.22 and earlier are affected by CVE-2025-43582.