Executive brief
Adobe Substance 3D Painter, a professional 3D texturing and painting application, is affected by a security flaw that could allow an attacker to take control of a user's computer. To exploit this, an attacker must trick a user into opening a specially crafted malicious file. If successful, the attacker could execute unauthorized commands or install software with the same permissions as the logged-in user.
Technical details
An out-of-bounds write vulnerability (CWE-787) exists in Adobe Substance 3D Painter versions 12.0.2 and earlier. The flaw is triggered when the application processes a specially crafted file, leading to memory corruption. An attacker can leverage this to achieve arbitrary code execution in the context of the current user. Exploitation requires local delivery of a malicious file and user interaction (opening the file). Adobe has addressed this in version 12.0.3.
Affected products
- Adobe Substance 3D Painter 12.0.2 and earlier
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory