Executive brief
Adobe Substance3D Painter is a 3D digital art application used by designers and artists for texture painting and asset creation. A NULL pointer dereference vulnerability in Painter versions 11.1.2 and earlier can be triggered when opening a malicious file, causing the application to crash and disrupting creative work and project timelines.
Technical details
The vulnerability is a NULL pointer dereference in Substance3D Painter versions 11.1.2 and earlier. The flaw requires user interaction—specifically opening a specially crafted malicious file—to trigger the crash. An attacker can exploit this to cause a denial-of-service condition by crashing the application. The attack vector is local (file-based) and impacts availability of the application. Patches are expected to be available in later versions after 11.1.2.
Affected products
- Adobe Substance3D Painter 11.1.2 and earlier
Timeline
- 2026-03-10: disclosed