Executive brief
Substance3D Designer, Adobe's professional 3D content creation tool, is vulnerable to a heap-based buffer overflow that allows an attacker to execute arbitrary code with the privileges of the user running the application. An attacker must trick a user into opening a specially crafted malicious file to trigger the vulnerability, making this a practical risk for designers and artists who may receive files from untrusted sources.
Technical details
A heap-based buffer overflow vulnerability exists in Adobe Substance3D Designer, allowing arbitrary code execution in the context of the current user. The vulnerability is triggered by parsing a malicious file that the user must open—no network access or elevated privileges are required for exploitation. The attacker must craft a specific file format that, when processed by the application, causes a buffer overrun on the heap, enabling arbitrary code execution with user-level privileges. User interaction (opening a file) is required to trigger the vulnerability.
Affected products
- Adobe Substance3D Designer
Timeline
- 2026-08-25: disclosed