CVE-2025-24441

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Mar 11, 2025
Updated: Apr 1, 2025
CWE ID 787

Summary

CVE-2025-24441 is a vulnerability affecting Substance3D's Sampler software, versions 4.5.2 and earlier. This issue involves an out-of-bounds write flaw that could lead to arbitrary code execution, granting attackers the ability to run malicious code on the affected system. However, exploitation of this vulnerability necessitates user interaction, as a victim would need to open a maliciously crafted file to trigger the exploit.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share