Executive brief
Substance3D Painter, a professional 3D painting and texturing application, contains a vulnerability that allows attackers to crash the application by tricking users into opening a malicious file. This causes service disruption and prevents artists from working until the application is restarted.
Technical details
The vulnerability is a NULL pointer dereference in Substance3D Painter versions 11.1.2 and earlier. The flaw occurs when the application processes a malicious or specially crafted file, leading to a crash. Exploitation requires user interaction—a victim must open the malicious file—making it a local attack vector. An attacker cannot remotely trigger this vulnerability or gain code execution; the impact is limited to denial-of-service (application crash). Patches for versions after 11.1.2 are available.
Affected products
- Adobe Substance3D Painter 11.1.2 and earlier
Timeline
- 2026-03-10: disclosed