Executive brief
Adobe Substance3D Sampler is a 3D design tool used by creative professionals to create and manage textures and materials. Versions 5.1.0 and earlier contain an out-of-bounds write flaw that allows attackers to execute arbitrary code on a user's system if they trick the victim into opening a specially crafted malicious file, potentially compromising the entire system and any sensitive project data.
Technical details
The vulnerability is an out-of-bounds write condition in Substance3D Sampler versions 5.1.0 and earlier, likely in the file parsing or deserialization routines. The flaw allows an attacker to write data beyond allocated memory boundaries, which can overwrite critical runtime structures and achieve arbitrary code execution. Exploitation requires user interaction—a victim must explicitly open a malicious file. The attack is triggered client-side with no authentication required. Upon successful exploitation, the attacker gains code execution with the privileges of the current user.
Affected products
- Adobe Substance3D Sampler 5.1.0 and earlier
Timeline
- 2026-01-13: disclosed