Executive brief
Adobe Substance3D Designer, a professional 3D design and content creation tool, is affected by an out-of-bounds write vulnerability. An attacker could exploit this flaw by crafting a malicious file that, when opened by a user, executes arbitrary code with the privileges of the logged-in designer, potentially compromising the user's system and access to design assets.
Technical details
This vulnerability is an out-of-bounds write flaw in Adobe Substance3D Designer that can lead to arbitrary code execution in the user's security context. The vulnerability requires user interaction, as a victim must open a specially crafted malicious file to trigger the exploit. The out-of-bounds write occurs during file processing, allowing an attacker to overwrite memory and redirect execution flow. No information is available on patch status from the provided references, though Adobe typically issues security updates through their APSB advisories.
Affected products
- Adobe Substance3D Designer
Timeline
- 2026-08-25: disclosed