Executive brief
Substance3D Designer, Adobe's professional 3D design and editing tool, contains a NULL pointer dereference flaw that crashes the application when processing a malicious file. An attacker can exploit this by distributing a crafted file that, when opened by a designer, causes the application to crash and disrupt their work.
Technical details
The vulnerability is a NULL pointer dereference affecting Substance3D Designer versions 15.1.0 and earlier. The flaw is triggered when the application attempts to process a specially crafted file, resulting in a crash that leads to denial of service. Exploitation requires user interaction—specifically, a victim must open a malicious file for the vulnerability to be triggered. The attack vector is local and does not require authentication or elevated privileges beyond the ability to deliver a file to the target.
Affected products
- Adobe Substance3D Designer 15.1.0 and earlier
Timeline
- 2026-02-10: disclosed