Executive brief
Adobe Substance3D Designer is a 3D design and modeling tool used by creative professionals to develop digital assets. A heap buffer overflow vulnerability in the application could allow an attacker to execute arbitrary code with the privileges of the user running the application, if the victim opens a malicious design file.
Technical details
The vulnerability is a heap-based buffer overflow in Adobe Substance3D Designer that can be triggered by parsing specially crafted input within a design file. The attack requires user interaction—specifically, the victim must open a malicious file in the application. Successful exploitation allows an attacker to achieve arbitrary code execution in the context of the current user. The vulnerability is not known to be actively exploited in the wild.
Affected products
- Adobe Substance3D Designer
Timeline
- 2026-08-25: disclosed