CVE-2025-54280: Substance3D - Viewer | Out-of-bounds Write (CWE-787)
Published Oct 14, 2025
·Updated
Substance3D - Viewer versions 0.25.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
2 affected components
Substance3D Viewer<0.25.2
Adobe Substance 3d Viewer<=0.25.2
Event History
Oct 14, 2025
CVE Published
via MITRE·07:07 PM
Data Sourced
via MITRE·07:07 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-54280?
CVE-2025-54280 has a high severity due to its potential for arbitrary code execution.
2
How do I fix CVE-2025-54280?
To fix CVE-2025-54280, upgrade Substance3D Viewer to version 0.25.3 or later.
3
What does CVE-2025-54280 affect?
CVE-2025-54280 affects Substance3D Viewer versions 0.25.2 and earlier.
4
Is user interaction required for CVE-2025-54280 exploitation?
Yes, exploitation of CVE-2025-54280 requires user interaction by opening a malicious file.
5
What risk do users face with CVE-2025-54280?
Users face the risk of arbitrary code execution in the context of the current user with CVE-2025-54280.