Executive brief
Substance3D Modeler is Adobe's 3D design tool used by creative professionals to build and model 3D assets. Versions 1.22.4 and earlier contain a memory vulnerability that allows attackers to execute arbitrary code on a user's system if they trick the user into opening a malicious 3D model file. This could lead to complete system compromise, data theft, and loss of control over the affected workstation.
Technical details
The vulnerability is an out-of-bounds write flaw in Substance3D Modeler that enables arbitrary code execution within the context of the current user. The vulnerability requires user interaction—specifically, the victim must open a malicious file—to be exploited. The attack vector is local, requiring the attacker to deliver a crafted file to the target. No network exploitation or elevated privileges are required beyond standard user access. A patch is available for versions 1.22.5 and later.
Affected products
- Adobe Substance3D Modeler 1.22.4 and earlier
Timeline
- 2026-01-13: disclosed
- 2026-01-13: patched: Fixed in version 1.22.5 and later