Executive brief
Adobe Substance3D Painter is a digital content creation tool used by 3D artists and designers. An out-of-bounds write vulnerability could allow an attacker to execute arbitrary code with the permissions of the current user if a victim opens a malicious file. Exploitation requires social engineering but could lead to complete compromise of the affected workstation.
Technical details
The vulnerability is an out-of-bounds write flaw in Substance3D Painter that permits arbitrary code execution. The attack vector requires user interaction: a victim must open a specially crafted malicious file to trigger the vulnerability. Once exploited, an attacker gains code execution in the context of the logged-in user. The vulnerability impacts the integrity and confidentiality of systems running affected versions of Substance3D Painter.
Affected products
- Adobe Substance3D Painter
Timeline
- 2026-08-25: disclosed