ZeroHour

CVE-2026-83959

large

Heap Buffer Overflow in Adobe Substance 3D Sampler Allows Arbitrary Code Execution

CVSS 3.1
7.8 high
EPSS
<1%p7
Published
()
Modified
AI analysis

Adobe Substance 3D Sampler, a desktop application for creating and editing 3D materials and textures, contains a heap-based buffer overflow (CWE-122) that corrupts memory when the application processes malicious content. Exploitation requires user interaction: a victim must open a malicious file with a vulnerable version of the application. A successful attack lets the adversary execute arbitrary code with the privileges of the user running Sampler, with high impact on confidentiality, integrity, and availability within that user's context. Users running the application and opening files from untrusted sources, such as downloaded 3D assets or shared project files, are the affected population. As of this data there is no known public proof-of-concept, the EPSS score is low (0.2% probability of exploitation within 30 days, 7th percentile), and the flaw is not in CISA's KEV catalog, so no in-the-wild exploitation is confirmed.

What to do: Upgrade Substance 3D Sampler to the fixed release listed in Adobe's security bulletin, since the exact patched version was not included in the data provided here. Until patched, avoid opening project, material, or asset files obtained from untrusted or unverified sources with vulnerable builds. Check your environment's software inventory (including Creative Cloud-managed deployments) for machines with older Sampler installations and prioritize workstations that regularly import third-party 3D assets.

Affected
Adobe Substance 3D Sampler
Estimated exposure
largelikely on the order of hundreds of thousands of desktop users; exact counts unpublished — Substance 3D Sampler is a commercial creative tool in Adobe's Substance 3D suite, widely deployed in game development and VFX pipelines whose user base has historically been cited in the hundreds of thousands, but Adobe does not publish…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Vendors
adobe
Products
substance 3d sampler
Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.