Description
The application contains an out-of-bounds write vulnerability that can be exploited by an attacker to cause the program to write data past the end of an allocated memory buffer. This can lead to arbitrary code execution.
Published: 2026-07-07
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An out-of-bounds write flaw in the Proteus application can allow an attacker to write data beyond a memory buffer, potentially leading to arbitrary code execution. The weakness is a classic buffer overflow problem classified as CWE-787. Based on the description, it is inferred that an attacker could supply crafted input that triggers the buffer overrun, compromising the integrity of the running process and allowing code to be executed with the application's privileges.

Affected Systems

The issue affects Labcenter Proteus installations that are not running the latest 9.2 SPO release. All versions before 9.2 SPO are identified as vulnerable; the vendor’s advisory specifies that upgrading to 9.2 SPO or later resolves the flaw.

Risk and Exploitability

The vulnerability has a CVSS score of 8.4, indicating high severity. The EPSS score of < 1% suggests that exploitation is unlikely but not impossible. The issue is not listed in the CISA KEV catalog, implying no confirmed exploitation yet. Based on the description, it is inferred that an attacker who can supply crafted input—such as a user interaction or a malicious data file processed by the software—may trigger the overflow and gain control of the process.

Generated by OpenCVE AI on July 26, 2026 at 18:51 UTC.

Remediation

Vendor Solution

Labcenter recommends ensuring you are using the latest version (9.2 SPO) of the software. Version can be found by looking at the bottom left of the Proteus home page (Version 8 or higher) or by selecting the About ISIS or About ARES option from the Help menu. Update notifications appear in the new and information section of the home page where you can activate the download and installation directly. If you have questions or need help please contact Labcenter or your local distributor.


OpenCVE Recommended Actions

  • Upgrade to the Labcenter Proteus 9.2 SPO release or newer, which contains the out-of-bounds write fix.
  • Download the latest installer from the Labcenter website and run it manually if automatic update notifications do not appear.
  • Limit execution of the software by restricting or sandboxing it to reduce exposure to potentially malicious input until an update is available.

Generated by OpenCVE AI on July 26, 2026 at 18:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 08 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 07 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Labcenter
Labcenter proteus
Vendors & Products Labcenter
Labcenter proteus

Tue, 07 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Description The application contains an out-of-bounds write vulnerability that can be exploited by an attacker to cause the program to write data past the end of an allocated memory buffer. This can lead to arbitrary code execution.
Title Out-of-bounds write in Labcenter Proteus
Weaknesses CWE-787
References
Metrics cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Labcenter Proteus
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-07-08T13:03:58.052Z

Reserved: 2026-06-03T15:40:50.751Z

Link: CVE-2026-42953

cve-icon Vulnrichment

Updated: 2026-07-08T13:03:48.472Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T19:00:02Z

Weaknesses