CVE-2026-21335

7.8

Adobe · Substance 3D Designer

Adobe Substance 3D Designer versions 15.1.0 and earlier contain an out-of-bounds write vulnerability that could allow arbitrary code execution through the opening of a malicious file.

Executive summary

Adobe Substance 3D Designer is affected by a critical out-of-bounds write vulnerability that can lead to arbitrary code execution if a user opens a specially crafted file.

Vulnerability

This vulnerability is an out-of-bounds write (CWE-787) flaw occurring within the application. It requires user interaction, specifically the opening of a malicious file by a victim, to trigger the execution of arbitrary code in the context of the current user.

Business impact

Successful exploitation allows an attacker to execute arbitrary code with the privileges of the victim, which could lead to a full system compromise. Given the CVSS score of 7.8, the risk is high because it provides a mechanism for threat actors to gain unauthorized control over user workstations and potentially pivot into internal network environments.

Remediation

Immediate Action: Update Adobe Substance 3D Designer to version 15.1.2 or later to apply the necessary security fixes.

Proactive Monitoring: Monitor endpoint activity for unusual process execution or unauthorized file modifications originating from the Substance 3D Designer application.

Compensating Controls: Implement strict email and file-transfer filtering to prevent users from opening untrusted or unsolicited project files from unknown sources.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Organizations should prioritize patching all instances of Adobe Substance 3D Designer to the fixed version, 15.1.2. Users should be cautioned against opening files from untrusted sources, as the primary attack vector relies on the successful opening of a malicious file.

More Adobe CVEs

Sources