Executive brief
Adobe Substance3D Sampler is a 3D material creation tool used by designers and artists in digital content production. The application contains an out-of-bounds write vulnerability that could allow an attacker to execute arbitrary code on a user's system when they open a specially crafted malicious file, potentially compromising sensitive project files and system integrity.
Technical details
Substance3D Sampler is affected by an out-of-bounds write vulnerability in file parsing logic. The vulnerability is triggered when a user opens a malicious file, allowing an attacker to write data beyond allocated memory boundaries. Successful exploitation results in arbitrary code execution in the context of the current user. User interaction is required, as a victim must explicitly open the malicious file. No remote exploitation is possible; the attack vector is local and file-based. Patches are available from Adobe.
Affected products
- Adobe Substance3D Sampler
Timeline
- 2026-08-25: disclosed: CVE-2026-48418 published