CVE-2026-48425: Substance3D - Sampler | Heap-based Buffer Overflow (CWE-122)
Published Aug 25, 2026
·Updated
Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
1 affected component
Substance3D - Sampler
Event History
Aug 25, 2026
CVE Published
via MITRE·05:46 PM
Data Sourced
via MITRE·05:46 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who is exposed to exploitation?
Users of Substance3D - Sampler are exposed when they open a malicious file. Successful exploitation can execute code in the context of the current user.
2
Does exploitation require an attacker to have local access or credentials?
The provided vector indicates local attack access and no privileges required, but exploitation also requires the victim to interact with the malicious file by opening it.
3
What is the potential impact of successful exploitation?
A successful heap-based buffer overflow could allow arbitrary code execution with the confidentiality, integrity, and availability privileges of the current user.