Executive brief
Substance3D Modeler is Adobe's 3D modeling application used by designers and artists. A vulnerability allows attackers to execute arbitrary code on a user's system if they trick a user into opening a specially crafted malicious file, potentially compromising the designer's workstation and any projects or credentials stored on it.
Technical details
Substance3D Modeler versions 1.22.4 and earlier contain an out-of-bounds write vulnerability in file handling code. The vulnerability is triggered when a victim opens a malicious file, causing memory corruption that can be leveraged for arbitrary code execution with the privileges of the current user. The attack requires user interaction (opening a file) and succeeds in the context of the logged-in user. A patch is available in versions after 1.22.4.
Affected products
- Adobe Substance3D Modeler 1.22.4 and earlier
Timeline
- 2026-01-13: disclosed