Executive brief
Adobe Substance3D Painter is a 3D art and design application used by creative professionals. A heap buffer overflow vulnerability allows an attacker to execute arbitrary code on a victim's machine if they can trick the user into opening a malicious file, potentially compromising the artist's work, system integrity, and credentials.
Technical details
The vulnerability is a heap-based buffer overflow in Adobe Substance3D Painter that can be triggered by parsing a specially crafted file. An attacker with no special privileges can exploit this by crafting a malicious file and distributing it to users. The attack requires user interaction (opening the malicious file), but upon successful exploitation, the attacker can achieve arbitrary code execution in the context of the current user. No details on affected versions or patch status are available from the provided advisory references.
Affected products
- Adobe Substance3D Painter <UNKNOWN>
Timeline
- 2026-08-25: disclosed