Executive brief
Adobe Substance 3D Designer, a professional tool for creating 3D materials and textures, is affected by a security flaw that could allow an attacker to take control of a user's computer. To exploit this, an attacker must trick a user into opening a specially crafted malicious file. Successful exploitation could lead to unauthorized data access or the installation of malicious software in the context of the victim's account.
Technical details
An out-of-bounds write vulnerability (CWE-787) exists in Adobe Substance 3D Designer versions 15.1.0 and earlier. The flaw is triggered when the application processes a specially crafted file, leading to memory corruption. An attacker can leverage this to execute arbitrary code with the privileges of the current user. Exploitation requires local access and user interaction, specifically the opening of a malicious file. Adobe has addressed this issue in later versions.
Affected products
- Adobe Substance 3D Designer 15.1.0 and earlier
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory