Executive brief
Adobe Substance3D Sampler is a 3D material and texture creation tool used by designers and artists. A heap buffer overflow vulnerability allows an attacker to execute arbitrary code on a user's system by tricking them into opening a specially crafted malicious file, potentially compromising their system and data.
Technical details
The vulnerability is a heap-based buffer overflow in Adobe Substance3D Sampler that permits arbitrary code execution within the security context of the current user. The flaw is triggered when a victim opens a malicious file, indicating the attack vector requires user interaction and file handling functionality. No authentication is required beyond convincing the user to open the file. An attacker can achieve remote code execution with the privileges of the user running the application. Patch availability details are not confirmed from the provided sources.
Affected products
- Adobe Substance3D Sampler
Timeline
- 2026-08-25: disclosed