Executive brief
Adobe Substance3D Stager is a 3D asset preparation tool used by designers and developers to stage 3D content. Versions 3.1.7 and earlier contain an out-of-bounds write vulnerability that allows an attacker to execute arbitrary code when a victim opens a specially crafted malicious file. This could lead to unauthorized access, data theft, or system compromise.
Technical details
An out-of-bounds write vulnerability exists in Substance3D Stager versions 3.1.7 and earlier. The vulnerability is triggered when processing a malicious file, allowing an attacker to write data outside allocated memory boundaries. This leads to arbitrary code execution with the privileges of the current user. Exploitation requires user interaction—a victim must open a malicious file. The vulnerability affects Windows and/or macOS systems running the affected versions. A patch is expected to be available through Adobe's standard security update channels.
Affected products
- Adobe Substance3D Stager 3.1.7 and earlier
Timeline
- 2026-03-10: disclosed