Executive brief
Adobe Substance3D Sampler is a 3D material creation tool used by designers and artists. A heap buffer overflow vulnerability in versions 5.1.3 and earlier could allow an attacker to execute arbitrary code on a user's system if they open a malicious file, potentially compromising the user's account and data.
Technical details
A heap-based buffer overflow exists in Adobe Substance3D Sampler versions 5.1.3 and earlier. The vulnerability is triggered when the application processes a specially crafted input file, allowing an attacker to overflow a heap buffer and overwrite adjacent memory. Exploitation requires user interaction—the victim must open a malicious file. Successful exploitation results in arbitrary code execution in the context of the current user. No information on patch availability is provided in the advisory.
Affected products
- Adobe Substance3D Sampler 5.1.3 and earlier
Timeline
- 2026-08-27: disclosed