Impact
An out-of-bounds write flaw in the Proteus application can allow an attacker to write data beyond a memory buffer, potentially leading to arbitrary code execution. The weakness is a classic buffer overflow problem classified as CWE-787. Based on the description, it is inferred that an attacker could supply crafted input that triggers the buffer overrun, compromising the integrity of the running process and allowing code to be executed with the application's privileges.
Affected Systems
The issue affects Labcenter Proteus installations that are not running the latest 9.2 SPO release. All versions before 9.2 SPO are identified as vulnerable; the vendor’s advisory specifies that upgrading to 9.2 SPO or later resolves the flaw.
Risk and Exploitability
The vulnerability has a CVSS score of 8.4, indicating high severity. The EPSS score of < 1% suggests that exploitation is unlikely but not impossible. The issue is not listed in the CISA KEV catalog, implying no confirmed exploitation yet. Based on the description, it is inferred that an attacker who can supply crafted input—such as a user interaction or a malicious data file processed by the software—may trigger the overflow and gain control of the process.
OpenCVE Enrichment