Executive brief
Adobe Substance3D Sampler is a 3D material design tool used by artists and developers to create textures and materials. An out-of-bounds write vulnerability allows attackers to execute arbitrary code on a user's computer if they trick the user into opening a malicious file, potentially compromising design projects, stealing intellectual property, or gaining system access.
Technical details
Substance3D Sampler is affected by an out-of-bounds write vulnerability (CWE-787) that can be exploited to achieve arbitrary code execution within the context of the current user. The vulnerability is triggered when a user opens a malicious file, making social engineering the primary attack vector. No remote exploitation is possible without user interaction. Patches are expected to be available from Adobe; users should apply security updates when released.
Affected products
- Adobe Substance3D Sampler
Timeline
- 2026-08-25: disclosed