Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
5.5

CVE-2024-53006: Substance3D Modeler Crashes from Malicious Files

CVE-2024-53006
Summary

Versions 1.14.1 and earlier of Substance3D Modeler are vulnerable to a bug that lets attackers crash the program by tricking users into opening a malicious file. This could cause the application to stop working until it's restarted. To stay safe, update to the latest version of Substance3D Modeler.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
adobe substance_3d_modeler <= 1.14.1
cpe:2.3:a:adobe:substance_3d_modeler:*:*:*:*:*:*:*:*
Original title
Substance3D - Modeler versions 1.14.1 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vuln...
Original description
Substance3D - Modeler versions 1.14.1 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd CVSS3.1 5.5
Vulnerability type
CWE-476 NULL Pointer Dereference
Published: 10 Dec 2024 · Updated: 15 Jun 2026 · First seen: 7 Mar 2026