Executive brief
Substance3D Modeler, Adobe's 3D design and modeling tool, contains an out-of-bounds write vulnerability that allows arbitrary code execution. An attacker can exploit this by crafting a malicious file that, when opened by a user, executes code with the same privileges as the victim, potentially leading to system compromise or data theft.
Technical details
An out-of-bounds write flaw in Substance3D Modeler permits an unauthenticated attacker to achieve arbitrary code execution in the context of the current user. The vulnerability requires user interaction—specifically opening a malicious file—and does not involve network-based attack vectors. No authenticated access or special privileges are required beyond the ability to deliver a crafted file to the victim.
Affected products
- Adobe Substance3D Modeler <UNKNOWN>
Timeline
- 2026-09-22: disclosed