Executive brief
Adobe Substance3D Modeler, a 3D modeling design tool, contains an out-of-bounds write vulnerability that could allow an attacker to execute arbitrary code with user privileges. An attacker must trick a user into opening a malicious file to trigger the vulnerability. Successful exploitation could lead to complete system compromise depending on the user's access level.
Technical details
The vulnerability is an out-of-bounds write flaw in Substance3D Modeler that can be triggered by opening a specially crafted file. The attack requires user interaction (opening a malicious file) and results in arbitrary code execution in the context of the current user. A patch has been released by Adobe.
Affected products
- Adobe Substance3D Modeler
Timeline
- 2026-09-22: disclosed