Executive brief
Substance3D Stager is a 3D asset preparation tool used by designers and creative professionals. A flaw in how it processes crafted files allows reading past the end of allocated memory, potentially enabling attackers to execute arbitrary code on a user's system when they open a malicious file. The attack requires user interaction but poses a significant risk to creative workflows and systems handling sensitive design assets.
Technical details
The vulnerability is an out-of-bounds read (CWE-125) in Substance3D Stager's file parsing functionality that permits reading past the end of an allocated memory structure. The root cause lies in insufficient bounds checking when processing crafted input files. The attack vector is local with user interaction required—a victim must open a malicious file. Successful exploitation allows code execution in the context of the current user. The vulnerability affects versions 3.1.6 and earlier; patched versions should be available from Adobe.
Affected products
- Adobe Substance3D Stager 3.1.6 and earlier
Timeline
- 2026-02-10: disclosed