Sceawere

Vulnerability Detail

CVE-2026-34674UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Substance3D Sampler Heap Buffer Overflow

Vulnerability Metadata

Severity
High
Score / CVSS
7.8
Creation Date
1h ago
Vendor
Adobe
Product
Adobe Substance 3D Sampler
Attack Type
Heap-based Buffer Overflow (CWE-122)
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Substance3D - Sampler versions 5.1.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.8",
  "pubDate": "2026-08-27T17:18:10.973Z",
  "pubdate": "2026-08-27T17:18:10.973Z",
  "executiveSummary": "Substance3D Sampler versions 5.1.3 and earlier are susceptible to a critical heap-based buffer overflow vulnerability.\nThis vulnerability allows for arbitrary code execution within the security context of the logged-in user.\nThe flaw stems from improper handling of malformed input files, which triggers a heap memory corruption when processed by the application.\nThe primary attack vector requires successful user interaction, specifically the opening of a specially crafted malicious file by an authenticated user.\nUpon successful exploitation, an attacker could achieve unauthorized code execution, potentially leading to a full system compromise, data exfiltration, or the installation of persistent malicious software.\nThe risk profile is elevated due to the nature of the vulnerability allowing for arbitrary command execution under the user's privilege level.",
  "technicalDetails": "The vulnerability is classified as a heap-based buffer overflow, occurring within the file parsing logic of Substance3D Sampler versions 5.1.3 and earlier.\nThe root cause involves insufficient bounds checking when the application allocates and writes data into heap memory while processing input files. When an attacker provides a maliciously crafted file, the input data exceeds the allocated buffer size, resulting in an out-of-bounds write operation on the heap.\nThis corruption of heap metadata or adjacent memory structures provides a mechanism for an attacker to redirect control flow. By carefully positioning payload data, an attacker can overwrite critical application data structures or function pointers. When the application subsequently attempts to utilize these corrupted structures or invoke the overwritten pointers, it executes code supplied by the attacker.\nThe attack flow follows a specific sequence: First, the attacker creates a malicious file designed to trigger the overflow during the parsing phase. Second, the attacker induces a victim, operating the application with standard user privileges, to open this file. Third, the application's internal parsing engine encounters the malformed input, triggering the buffer overflow on the heap.\nThe exploitation phase leverages the resulting memory corruption to gain arbitrary code execution. Because the application runs within the security context of the current user, the attacker's payload inherits those same permissions. This allows the adversary to perform any action permitted by the current user, including modifying user data, installing persistent backdoors, or executing further system-level commands.\nNo authentication or specific network exposure is required to initiate the attack, as the primary vector is file-based local interaction. The vulnerability is effectively triggered by the application's ingestion of untrusted input. Consequently, the impact is confined to the workstation or local environment where the user interacts with the compromised software."
}
CVE-2026-34674: Substance3D Sampler Heap Buffer Overflow (HIGH Severity, CVSS: 7.8) - Sceawere