CVE-2026-83959
largeHeap Buffer Overflow in Adobe Substance 3D Sampler Allows Arbitrary Code Execution
Adobe Substance 3D Sampler, a desktop application for creating and editing 3D materials and textures, contains a heap-based buffer overflow (CWE-122) that corrupts memory when the application processes malicious content. Exploitation requires user interaction: a victim must open a malicious file with a vulnerable version of the application. A successful attack lets the adversary execute arbitrary code with the privileges of the user running Sampler, with high impact on confidentiality, integrity, and availability within that user's context. Users running the application and opening files from untrusted sources, such as downloaded 3D assets or shared project files, are the affected population. As of this data there is no known public proof-of-concept, the EPSS score is low (0.2% probability of exploitation within 30 days, 7th percentile), and the flaw is not in CISA's KEV catalog, so no in-the-wild exploitation is confirmed.
What to do: Upgrade Substance 3D Sampler to the fixed release listed in Adobe's security bulletin, since the exact patched version was not included in the data provided here. Until patched, avoid opening project, material, or asset files obtained from untrusted or unverified sources with vulnerable builds. Check your environment's software inventory (including Creative Cloud-managed deployments) for machines with older Sampler installations and prioritize workstations that regularly import third-party 3D assets.
| Adobe Substance 3D Sampler | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
- Vendors
- adobe
- Products
- substance 3d sampler
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.