Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2025-27172

CVE-2025-27172: Adobe Substance 3D Designer RCE Flaw

CVE-2025-27172 is an out-of-bounds write vulnerability in Adobe Substance 3D Designer that enables remote code execution. Attackers exploit this through malicious files to run arbitrary code in the user's context.

Published:

CVE-2025-27172 Overview

CVE-2025-27172 is an out-of-bounds write vulnerability [CWE-787] affecting Adobe Substance 3D Designer versions 14.1 and earlier. Successful exploitation allows arbitrary code execution in the context of the current user. The flaw triggers when a victim opens a crafted file in the affected application, making user interaction a prerequisite for exploitation. Adobe addressed the issue in security bulletin APSB25-22.

Critical Impact

Attackers who convince a user to open a malicious Substance 3D Designer file can execute arbitrary code with the privileges of the current user.

Affected Products

  • Adobe Substance 3D Designer 14.1
  • Adobe Substance 3D Designer versions prior to 14.1
  • Windows and macOS installations of Substance 3D Designer

Discovery Timeline

  • 2025-03-11 - CVE-2025-27172 published to NVD alongside Adobe Security Bulletin APSB25-22
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-27172

Vulnerability Analysis

The vulnerability is an out-of-bounds write [CWE-787] in Adobe Substance 3D Designer 14.1 and earlier. Out-of-bounds writes occur when an application writes data past the end or before the beginning of an allocated buffer. In Substance 3D Designer, this condition is reached during the parsing of a malformed project or asset file. An attacker controls the data written outside the intended buffer, which can corrupt adjacent memory structures such as function pointers, virtual tables, or heap metadata. This corruption enables arbitrary code execution in the security context of the user running the application.

Root Cause

The root cause is insufficient validation of structure or length fields within file formats parsed by Substance 3D Designer. When the application processes attacker-controlled offsets or sizes without proper boundary checks, it writes attacker-supplied bytes outside the allocated memory region. Adobe has not published the specific parser or file format component at fault. Refer to the Adobe Security Bulletin APSB25-22 for vendor-confirmed details.

Attack Vector

Exploitation requires local access and user interaction. The attacker delivers a malicious Substance 3D Designer file through phishing, a watering-hole site, a shared asset repository, or a removable drive. The victim opens the file in a vulnerable version of Substance 3D Designer, which triggers the out-of-bounds write during parsing. Code executes with the privileges of the logged-in user, providing a foothold for credential theft, lateral movement, or persistence.

No public proof-of-concept exploit is available for CVE-2025-27172. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. See the Adobe Security Bulletin APSB25-22 for the vendor's technical summary.

Detection Methods for CVE-2025-27172

Indicators of Compromise

  • Unexpected child processes spawned by Adobe Substance 3D Designer.exe, particularly command interpreters such as cmd.exe, powershell.exe, or bash
  • Crashes or memory access violations logged when Substance 3D Designer opens project files (.sbs, .sbsar) from untrusted sources
  • Outbound network connections initiated by the Substance 3D Designer process to unfamiliar hosts shortly after a file is opened

Detection Strategies

  • Inventory installed versions of Substance 3D Designer and flag any host running 14.1 or earlier
  • Hunt for Substance 3D Designer process executions that load unusual modules or write executable files to user-writable directories
  • Inspect email gateways and file-sharing platforms for Substance 3D Designer asset files originating from external or untrusted senders

Monitoring Recommendations

  • Enable process creation logging (Windows Event ID 4688 or Sysmon Event ID 1) to capture parent-child relationships involving the Substance 3D Designer binary
  • Monitor user directories for newly written executables, scripts, or scheduled tasks created shortly after the application opens a file
  • Correlate endpoint telemetry with email and web proxy logs to identify the delivery vector of suspicious .sbs or .sbsar files

How to Mitigate CVE-2025-27172

Immediate Actions Required

  • Upgrade Adobe Substance 3D Designer to the version specified in Adobe Security Bulletin APSB25-22
  • Restrict opening of Substance 3D Designer files received from external or untrusted sources until patching is complete
  • Run Substance 3D Designer under standard user accounts to limit the impact of code execution

Patch Information

Adobe released a fixed version of Substance 3D Designer addressing CVE-2025-27172 in security bulletin APSB25-22. Administrators should apply the update across all endpoints with Substance 3D Designer installed. Full vendor guidance is available at the Adobe Security Bulletin APSB25-22.

Workarounds

  • Block delivery of Substance 3D Designer project and archive file extensions (.sbs, .sbsar) at email and web gateways when sourced externally
  • Apply application allowlisting to restrict execution of Substance 3D Designer to authorized users and workstations
  • Enforce least-privilege account policies so that exploitation does not yield administrative privileges

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.