Executive brief
Adobe Substance3D Designer is a professional 3D design application used to create digital assets and visual content. The application contains an out-of-bounds write vulnerability that could allow an attacker to execute arbitrary code with the privileges of the user running the application. Exploitation requires a user to open a malicious file, making this a delivery vector for targeted attacks on creative professionals.
Technical details
Substance3D Designer is vulnerable to an out-of-bounds write flaw in its file parsing logic. The vulnerability exists in the file handling mechanism and is triggered when a victim opens a specially crafted malicious file. An attacker can exploit this memory corruption issue to overwrite memory regions and achieve arbitrary code execution within the security context of the current user. The attack requires user interaction (opening a file), but no authentication is required. Patches or mitigations should be applied as released by Adobe.
Affected products
- Adobe Substance3D Designer
Timeline
- 2026-08-25: disclosed