Executive brief
Adobe Substance 3D Sampler, a professional tool used for creating 3D materials from real-world images, is affected by a security flaw that could allow an attacker to take control of a user's computer. To exploit this, an attacker would need to trick a user into opening a specially crafted malicious file. If successful, the attacker could run unauthorized commands or software with the same permissions as the logged-in user.
Technical details
An out-of-bounds write vulnerability (CWE-787) exists in Adobe Substance 3D Sampler versions 6.0.0 and earlier. The flaw is triggered when the application processes a specially crafted file, leading to memory corruption. An attacker can leverage this to execute arbitrary code in the context of the current user. This is a local attack vector that requires user interaction, specifically the opening of a malicious file. Adobe has addressed this issue in newer versions, and users are encouraged to update to the latest release.
Affected products
- Adobe Substance 3D Sampler 6.0.0 and earlier
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory