Executive brief
Adobe Substance3D Modeler is a 3D design and modeling tool used by creative professionals. An out-of-bounds write vulnerability allows attackers to execute arbitrary code with the privileges of the current user by tricking a victim into opening a specially crafted file. This could allow an attacker to compromise a designer's workstation and access sensitive design files or escalate privileges.
Technical details
The vulnerability is an out-of-bounds write in Substance3D Modeler that can be triggered when processing a malicious file. Exploitation requires user interaction to open the crafted file, and results in arbitrary code execution in the context of the logged-in user. A patch is available from Adobe.
Affected products
- Adobe Substance3D Modeler <UNKNOWN>
Timeline
- 2026-09-22: disclosed