Executive brief
Adobe Substance3D Sampler is a 3D material and texture creation tool used by designers and artists. A heap buffer overflow vulnerability allows an attacker to execute arbitrary code on a user's machine when the victim opens a specially crafted malicious file, potentially compromising the user's system and any sensitive projects or data being worked on.
Technical details
Substance3D Sampler contains a heap-based buffer overflow vulnerability in file parsing that allows arbitrary code execution. The vulnerability is triggered when processing a malicious file, requiring user interaction (opening the file) to exploit. A successful exploit executes code in the context of the current user, potentially leading to system compromise. No evidence of active exploitation in the wild has been reported at this time, and patches should be available from Adobe.
Affected products
- Adobe Substance3D Sampler
Timeline
- 2026-09-03: disclosed