Executive brief
Adobe Substance3D Sampler is a 3D content creation tool used by designers and artists. A heap buffer overflow vulnerability allows attackers to execute arbitrary code on a user's system if they trick the user into opening a malicious file, potentially compromising creative projects, intellectual property, and the underlying workstation.
Technical details
This vulnerability is a heap-based buffer overflow in Adobe Substance3D Sampler that can be triggered by processing a specially crafted file. The issue allows an attacker to overflow a heap buffer, potentially overwriting adjacent memory structures and achieving arbitrary code execution within the context of the logged-in user. Exploitation requires user interaction—a victim must be tricked into opening a malicious file. No public exploits have been reported in the wild as of the advisory date. Patches are expected to be available through Adobe security updates.
Affected products
- Adobe Substance3D Sampler
Timeline
- 2026-08-25: disclosed