CVE-2026-34675: Substance3D - Painter | Out-of-bounds Write (CWE-787)
Substance3D - Painter versions 12.0.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34675?
CVE-2026-34675 has a moderate severity rating due to the potential for arbitrary code execution after a successful exploitation.
How do I fix CVE-2026-34675?
To mitigate CVE-2026-34675, upgrade Adobe Substance 3D Painter to version 12.0.3 or later.
Who is affected by CVE-2026-34675?
CVE-2026-34675 affects Adobe Substance 3D Painter versions 12.0.2 and earlier.
What attack vector is associated with CVE-2026-34675?
Exploitation of CVE-2026-34675 requires user interaction, as it involves an out-of-bounds write.
What could happen if I do not address CVE-2026-34675?
Failure to address CVE-2026-34675 could allow an attacker to execute arbitrary code on the affected system.