Executive brief
Substance3D Stager is Adobe's 3D asset staging and preparation software used by designers and artists. Versions 3.1.6 and earlier contain an out-of-bounds read vulnerability triggered when opening malicious files, which could allow an attacker to execute code with the same privileges as the user. Exploitation requires a user to open a specially crafted file, making social engineering or file-delivery attacks the primary threat vector.
Technical details
The vulnerability is an out-of-bounds read flaw in Substance3D Stager's file parsing logic, affecting versions 3.1.6 and earlier. When processing a crafted input file, the parser reads past the end of an allocated memory structure, potentially exposing sensitive data or enabling code execution through memory corruption. The attack requires user interaction (opening a malicious file) and is not network-based. An attacker can leverage this vulnerability to execute arbitrary code in the context of the current user. Adobe has released patches to address this issue.
Affected products
- Adobe Substance3D Stager 3.1.6 and earlier
Timeline
- 2026-02-10: disclosed