Executive brief
Substance3D Painter is a professional 3D texture painting tool used by designers and artists. A vulnerability in versions 11.1.2 and earlier allows attackers to crash the application by tricking users into opening a malicious file, disrupting work and availability for affected users.
Technical details
A NULL pointer dereference vulnerability exists in Substance3D Painter versions 11.1.2 and earlier. The vulnerability can be triggered when a user opens a specially crafted malicious file, causing the application to attempt to access memory without proper validation. Exploitation requires user interaction—the victim must open the attacker-supplied file. The primary impact is denial-of-service (application crash), though no remote execution or data theft is possible from this flaw. Adobe has released patches to address this issue.
Affected products
- Adobe Substance3D Painter 11.1.2 and earlier
Timeline
- 2026-03-10: disclosed