Executive brief
Adobe Substance 3D Designer is a professional 3D modeling and texturing software used by graphics professionals and artists. A heap buffer overflow vulnerability in this application could allow attackers to execute arbitrary code on a user's machine if they trick them into opening a malicious file, potentially compromising sensitive project data and system integrity.
Technical details
This vulnerability is a heap-based buffer overflow in Adobe Substance 3D Designer that permits arbitrary code execution within the context of the user running the application. The vulnerability requires user interaction, specifically opening a crafted malicious file. This is a classic memory corruption bug where inadequate bounds checking on heap-allocated buffers allows an attacker-controlled input to overflow and corrupt adjacent memory, enabling code execution. No public exploit code is currently known to be circulating in the wild.
Affected products
- Adobe Substance 3D Designer
Timeline
- 2026-08-25: disclosed