---
id: CVE-2025-61803
title: >-
  Substance3D - Stager versions 3.1.4 and earlier are affected by an Integer
  Overflow or Wraparound vulnerability that could result in arbitrary code
  execution in the context of the current user
summary: >-
  Substance3D - Stager versions 3.1.4 and earlier are affected by an Integer
  Overflow or Wraparound vulnerability that could result in arbitrary code
  execution in the context of the current user. Exploitation of this issue
  requires user in…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-190
vendor: adobe
product: substance_3d_stager
affected:
  - substance_3d_stager < 3.1.5
patched:
  - substance_3d_stager 3.1.5
published: '2025-10-14'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T12:10:00.217'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-61803'
references:
  - url: >-
      https://helpx.adobe.com/security/products/substance3d_stager/apsb25-104.html
    label: psirt@adobe.com
tags:
  - nvd
epss: 0.00206
epssPercentile: 0.09827
ingestedAt: '2026-10-08T11:31:27.411Z'
---

## Overview

Substance3D - Stager versions 3.1.4 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

## Affected

- `substance_3d_stager < 3.1.5`

## Remediation

Upgrade past the affected range:

- `substance_3d_stager 3.1.5`
