Substance3D - Modeler versions 1.22.0 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. If the application uses an uncontrolled search path to locate critical resources such as programs, an attacker could modify that search path to point to a malicious program, which the targeted application would then execute. Exploitation of this issue does not require user interaction.
Metrics
Affected Vendors & Products
References
History
Thu, 14 Aug 2025 06:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 13 Aug 2025 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Adobe
Adobe substance 3d Modeler |
|
CPEs | cpe:2.3:a:adobe:substance_3d_modeler:*:*:*:*:*:*:*:* | |
Vendors & Products |
Adobe
Adobe substance 3d Modeler |
Tue, 12 Aug 2025 20:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Substance3D - Modeler versions 1.22.0 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. If the application uses an uncontrolled search path to locate critical resources such as programs, an attacker could modify that search path to point to a malicious program, which the targeted application would then execute. Exploitation of this issue does not require user interaction. | |
Title | Substance3D - Modeler | Uncontrolled Search Path Element (CWE-427) | |
Weaknesses | CWE-427 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: adobe
Published: 2025-08-12T20:36:07.533Z
Updated: 2025-08-13T20:12:59.292Z
Reserved: 2025-06-06T15:42:09.519Z
Link: CVE-2025-49571

Updated: 2025-08-13T14:13:35.597Z

Status : Analyzed
Published: 2025-08-12T21:15:31.043
Modified: 2025-08-13T18:15:50.600
Link: CVE-2025-49571

No data.