Adobe Substance 3D Stager Out-of-Bounds Read Vulnerability Leading to Memory Leak

Vulnerability

A memory leak vulnerability due to an out-of-bounds read has been identified in Adobe Substance 3D Stager versions through 3.1.3. This vulnerability could allow an attacker to disclose sensitive information. Exploitation requires user interaction, as a victim must open a malicious file.

Impact

Exploitation of this vulnerability could result in a memory leak, allowing for the unauthorized disclosure of sensitive information.

Remediation

Users are advised to update to Adobe Substance 3D Stager version 3.1.4. For managed environments, IT administrators can use the Adobe Admin Console to deploy Creative Cloud applications to end users.

Added: Sep 16, 2025, 6:39 PM
Updated: Sep 16, 2025, 6:39 PM

Vulnerability Rating

Custom Algorithm
spread
2.4
impact
2.5
exploitability
4.4
remediation
7.7
relevance
0.5
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.