Executive brief
Adobe Substance3D Modeler contains a stack-based buffer overflow vulnerability that allows an attacker to execute arbitrary code on a user's system. An attacker would need to trick a user into opening a specially crafted malicious file, after which the attacker gains full control over the application and the user's data.
Technical details
A stack-based buffer overflow exists in Substance3D Modeler that can be exploited through a malicious file. The vulnerability requires local user interaction to open the file, but results in arbitrary code execution in the context of the current user. No patch status information is available from the provided references.
Affected products
- Adobe Substance3D Modeler
Timeline
- 2026-09-22: disclosed