Executive brief
Substance3D Designer is Adobe's professional 3D design and modeling tool used by artists and designers. A null pointer dereference vulnerability in versions 15.1.0 and earlier can crash the application when a user opens a malicious file, disrupting work and causing denial of service.
Technical details
This vulnerability is a null pointer dereference flaw in Substance3D Designer versions 15.1.0 and earlier. The vulnerability is triggered when the application attempts to process a specially crafted file, causing it to dereference a null pointer and crash. Exploitation requires user interaction—specifically, a victim must open a malicious file provided by an attacker. This results in a denial-of-service condition where the application terminates unexpectedly. A patch is available in versions later than 15.1.0.
Affected products
- Adobe Substance3D Designer 15.1.0 and earlier
Timeline
- 2026-02-10: disclosed