Adobe Substance3D Modeler Uncontrolled Search Path Element Vulnerability Allowing Arbitrary Code Execution

Vulnerability

A vulnerability allowing arbitrary code execution has been identified in Adobe Substance3D Modeler versions through 1.21.0. This issue arises from an Uncontrolled Search Path Element vulnerability, where the application may be manipulated to load malicious resources, such as libraries or executables. Exploitation of this vulnerability requires user interaction, as a victim must open a crafted file.

Impact

Exploitation of this vulnerability could lead to arbitrary code execution in the context of the current user.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
4.4
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.