CVE-2025-64531: Substance3D - Stager | Use After Free (CWE-416)
Substance3D - Stager versions 3.1.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64531?
CVE-2025-64531 is considered a critical vulnerability due to its potential to allow arbitrary code execution.
How do I fix CVE-2025-64531?
To fix CVE-2025-64531, update Substance3D Stager to version 3.1.6 or later.
What causes CVE-2025-64531?
CVE-2025-64531 is caused by a Use After Free vulnerability in versions 3.1.5 and earlier of Substance3D Stager.
Who is affected by CVE-2025-64531?
Any user running Substance3D Stager version 3.1.5 or earlier may be affected by CVE-2025-64531.
What type of attack vector does CVE-2025-64531 utilize?
CVE-2025-64531 requires user interaction, specifically opening a malicious file, to exploit the vulnerability.