Executive brief
Substance3D Stager is Adobe's 3D asset preparation tool used by designers and artists. A use-after-free vulnerability in versions 3.1.5 and earlier allows arbitrary code execution when a user opens a malicious file, potentially compromising creative projects and system access.
Technical details
A use-after-free vulnerability exists in Substance3D Stager versions 3.1.5 and earlier, where freed memory is incorrectly accessed during file processing. The attack requires local user interaction—specifically opening a specially crafted file. Successful exploitation results in arbitrary code execution within the context of the current user. The vulnerability is classified as high severity (CVSS 7.8), though no active exploitation in the wild has been reported at time of disclosure.
Affected products
- Adobe Substance3D Stager 3.1.5 and earlier
Timeline
- 2026-01-13: disclosed