Executive brief
Adobe Substance3D Painter, a professional 3D painting and texturing application, contains an out-of-bounds write vulnerability that could allow an attacker to execute arbitrary code on a user's system. An attacker would need to trick a user into opening a specially crafted malicious file, but if successful, the attacker gains full control of the user's system and access to their data.
Technical details
The vulnerability is an out-of-bounds write flaw in Substance3D Painter that enables arbitrary code execution in the context of the current user. The attack requires user interaction—specifically, the victim must open a malicious file crafted by the attacker. No authentication or network access is required; exploitation depends solely on social engineering to convince a user to open the hostile file. Upon successful exploitation, an attacker can execute arbitrary code with the privileges of the affected user, potentially leading to system compromise.
Affected products
- Adobe Substance3D Painter
Timeline
- 2026-08-25: disclosed