CVE-2025-21137
CVSS 3.1 Score 7.8 of 10 (high)
Details
Summary
CVE-2025-21137 is a critical vulnerability affecting Substance3D's Designer versions 14.0 and prior. This issue involves a Heap-based Buffer Overflow, allowing an attacker to execute arbitrary code if a victim opens a malicious file. Successful exploitation requires user interaction, making this a significant threat to users who open unverified or suspicious files. This vulnerability could result in unauthorized system access, data theft, or other malicious activities. Users are urged to upgrade to the latest version of Substance3D Designer to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Substance 3D