CVE-2025-49571: Substance3D - Modeler | Uncontrolled Search Path Element (CWE-427)
Substance3D - Modeler versions 1.22.0 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. If the application uses an uncontrolled search path to locate critical resources such as programs, an attacker could modify that search path to point to a malicious program, which the targeted application would then execute. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49571?
CVE-2025-49571 is classified as a critical vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2025-49571?
To mitigate CVE-2025-49571, update Substance3D Modeler to version 1.22.1 or later.
What versions of Substance3D Modeler are affected by CVE-2025-49571?
Substance3D Modeler versions 1.22.0 and earlier are affected by CVE-2025-49571.
What type of vulnerability is CVE-2025-49571?
CVE-2025-49571 is an Uncontrolled Search Path Element vulnerability.
What could be the consequences of exploiting CVE-2025-49571?
Exploitation of CVE-2025-49571 could lead to arbitrary code execution in the context of the current user.