Executive brief
Substance3D Stager is Adobe's 3D asset preparation and staging tool used by designers and artists. A memory read vulnerability in file parsing could allow an attacker to crash the application or execute arbitrary code if a victim opens a specially crafted malicious file.
Technical details
The vulnerability is an out-of-bounds read (CWE-125) occurring when Substance3D Stager parses a crafted file, causing the application to read past the end of an allocated memory structure. The attack vector requires user interaction: a victim must open a malicious file to trigger the vulnerable code path. Successful exploitation could result in code execution in the context of the current user, potentially leading to arbitrary code execution with user privileges. Patches are available in versions after 3.1.6.
Affected products
- Adobe Substance3D Stager 3.1.6 and earlier
Timeline
- 2026-02-10: disclosed