Executive brief
Substance3D Modeler is Adobe's 3D design and modeling application used by creative professionals. A NULL pointer dereference flaw in versions 1.22.4 and earlier can crash the application when a user opens a specially crafted malicious file, causing temporary loss of work and disruption to design workflows.
Technical details
The vulnerability is a NULL pointer dereference in Substance3D Modeler version 1.22.4 and earlier. The flaw is triggered when processing a malicious file, leading to application denial-of-service (crash). Exploitation requires user interaction—specifically, a victim must open a crafted file, likely via email, file sharing, or a compromised source. The attacker cannot gain code execution or access sensitive data, but can disrupt availability and potentially cause loss of unsaved work. A patch is expected to be available through Adobe's security advisory.
Affected products
- Adobe Substance3D Modeler 1.22.4 and earlier
Timeline
- 2026-01-13: disclosed: Published on NVD
- 2026-01-13: advisory: Adobe APSB26-08 advisory