Executive brief
Substance3D Stager is Adobe's 3D asset creation and staging software. Versions 3.1.7 and earlier contain an out-of-bounds write flaw that allows an attacker to execute arbitrary code with the privileges of the user running the application, triggered by opening a malicious file.
Technical details
This is an out-of-bounds write vulnerability in Adobe Substance3D Stager versions 3.1.7 and earlier. The vulnerability allows arbitrary code execution in the context of the current user. Exploitation requires user interaction—specifically, the victim must open a malicious file. No network vector is involved; the attack is local and user-initiated. An attacker can achieve arbitrary code execution with the victim's privileges by crafting a malicious file and socially engineering the user to open it.
Affected products
- Adobe Substance3D Stager 3.1.7 and earlier
Timeline
- 2026-03-10: disclosed