Executive brief
Substance3D Designer is Adobe's professional 3D design and texturing software used by artists and designers. A flaw in versions 15.0.3 and earlier allows attackers to execute arbitrary code on a user's computer by crafting a malicious file that, when opened, triggers an out-of-bounds memory write. An attacker would need to trick a user into opening a malicious file, potentially compromising the system and any work stored on it.
Technical details
The vulnerability is an out-of-bounds write flaw in Substance3D Designer versions 15.0.3 and earlier. The root cause appears to be improper bounds checking during file parsing or processing. Attack vector is local and requires user interaction: a victim must explicitly open a specially crafted malicious file. Successful exploitation allows arbitrary code execution in the context of the current user. The flaw affects versions up to and including 15.0.3; patch status for newer versions is implied but details are not available in the advisory.
Affected products
- Adobe Substance3D Designer 15.0.3 and earlier
Timeline
- 2026-01-13: disclosed