Executive brief
Adobe Substance3D Designer, a 3D design and content creation application, contains a heap-based buffer overflow vulnerability that can lead to arbitrary code execution when a user opens a malicious file. An attacker could craft a specially-designed file that, when opened by a legitimate user, executes unauthorized code with the privileges of that user, potentially compromising the system and exposing sensitive design assets or data.
Technical details
This is a heap-based buffer overflow vulnerability in Adobe Substance3D Designer's file parsing logic. The vulnerability occurs when the application processes a malicious file that triggers a buffer overflow in heap memory. The attack requires user interaction—specifically, a victim must open a crafted malicious file for exploitation to occur. Successful exploitation allows an attacker to execute arbitrary code in the context of the current user. No network connectivity is required; the attack surface is limited to local file handling. Adobe has assigned this vulnerability CVE-2026-48432 with a CVSS score of 7.8 (high severity).
Affected products
- Adobe Substance3D Designer
Timeline
- 2026-08-25: disclosed