Executive brief
Substance3D Designer is Adobe's professional 3D design software used by artists and designers to create digital assets. Versions 15.1.0 and earlier contain a memory corruption flaw that could allow attackers to execute arbitrary code on a user's system if they trick the user into opening a specially crafted file. This could lead to complete compromise of the designer's workstation and theft of sensitive design files or credentials.
Technical details
The vulnerability is an out-of-bounds write (heap buffer overflow) in Substance3D Designer versions 15.1.0 and earlier. The flaw is triggered when processing maliciously crafted input files, allowing an attacker to write memory beyond the intended buffer boundaries. Exploitation requires user interaction—specifically, a victim must open a malicious file. Successful exploitation leads to arbitrary code execution in the context of the current user with no additional privileges required. Patches should be available from Adobe; update to version 15.1.1 or later.
Affected products
- Adobe Substance3D Designer 15.1.0 and earlier
Timeline
- 2026-02-10: disclosed