Executive brief
Substance3D Designer is Adobe's 3D design and texturing application used by artists and designers. Versions 15.0.3 and earlier contain a memory read vulnerability that could expose sensitive data when a user opens a malicious design file. While exploitation requires user interaction, the flaw could lead to disclosure of confidential project data or system information.
Technical details
The vulnerability is an out-of-bounds read in Substance3D Designer's file parsing logic, affecting versions 15.0.3 and earlier. An attacker can craft a malicious design file that triggers the out-of-bounds read when opened by a victim, allowing memory disclosure. The attack requires user interaction (opening the malicious file) and local execution context; the vulnerability does not provide remote code execution or privilege escalation. Adobe has patched this issue in versions later than 15.0.3.
Affected products
- Adobe Substance3D Designer 15.0.3 and earlier
Timeline
- 2026-01-13: disclosed