Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-49571

Опубликовано: 12 авг. 2025
Источник: nvd
CVSS3: 7.8
EPSS Низкий

Описание

Substance3D - Modeler versions 1.22.0 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. If the application uses an uncontrolled search path to locate critical resources such as programs, an attacker could modify that search path to point to a malicious program, which the targeted application would then execute. Exploitation of this issue does not require user interaction.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:adobe:substance_3d_modeler:*:*:*:*:*:*:*:*
Версия до 1.22.2 (исключая)

EPSS

Процентиль: 13%
0.00222
Низкий

7.8 High

CVSS3

Дефекты

CWE-427

Связанные уязвимости

CVSS3: 7.8
github
12 месяцев назад

Substance3D - Modeler versions 1.22.0 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. If the application uses an uncontrolled search path to locate critical resources such as programs, an attacker could modify that search path to point to a malicious program, which the targeted application would then execute. Exploitation of this issue does not require user interaction.

CVSS3: 7.8
fstec
12 месяцев назад

Уязвимость программного обеспечения для 3D-моделирования Adobe Substance 3D Modeler, связанная с неконтролируемым элементом пути поиска, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 13%
0.00222
Низкий

7.8 High

CVSS3

Дефекты

CWE-427