Executive brief
Adobe Substance3D Painter, a 3D painting and texturing software used by digital artists and designers, is vulnerable to an out-of-bounds read that can expose sensitive information from program memory. An attacker can exploit this by crafting a malicious file and tricking a user into opening it, potentially revealing confidential data or other sensitive information stored in the application's memory.
Technical details
This is an out-of-bounds read vulnerability in Adobe Substance3D Painter versions 11.1.2 and earlier. The vulnerability allows an attacker to read memory beyond the bounds of allocated buffers, potentially exposing sensitive data. Exploitation requires user interaction—specifically, a victim must open a malicious file in the affected application. An attacker can leverage this to access sensitive information stored in memory. Patches are available from Adobe for affected versions.
Affected products
- Adobe Substance3D Painter 11.1.2 and earlier
Timeline
- 2026-03-10: disclosed