CVE-2025-21155
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Published Feb 11, 2025
CWE ID 476
Summary
CVE-2025-21155 is a NULL Pointer Dereference vulnerability affecting Substance3D's Stager versions 3.1.0 and earlier. This issue can cause an application denial-of-service when an attacker successfully exploits it. The exploitation process requires user interaction, as the victim must open a maliciously crafted file to trigger the vulnerability. Consequently, this weakness poses a significant risk of crashing the application and denying legitimate users access to the affected system.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share