CVE-2025-54187: Substance3D - Painter | Out-of-bounds Write (CWE-787)
Substance3D - Painter versions 11.0.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54187?
CVE-2025-54187 is considered a critical vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2025-54187?
To mitigate CVE-2025-54187, upgrade Substance3D Painter to version 11.0.3 or later.
What versions of Substance3D Painter are impacted by CVE-2025-54187?
CVE-2025-54187 affects Substance3D Painter versions 11.0.2 and earlier.
What kind of attacks can exploit CVE-2025-54187?
CVE-2025-54187 can be exploited through user interaction by opening a malicious file that triggers the out-of-bounds write.
Who is vulnerable to CVE-2025-54187?
Any user of Substance3D Painter versions 11.0.2 or earlier is at risk of CVE-2025-54187 if they open a malicious file.