Impact
The vulnerability is a use‑after‑free flaw that corrupts memory while parsing crafted files, potentially allowing an attacker to execute arbitrary code within the process context of Proteus. It is classified as a CWE‑416 weakness and could be exploited to gain full system compromise if malicious input is supplied.
Affected Systems
The flaw affects Labcenter Proteus software versions prior to 9.2 SPO. Users running earlier releases are susceptible to this issue.
Risk and Exploitability
The CVSS score of 8.4 indicates a high severity, but the EPSS score of less than 1% suggests a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog, implying no known public exploits. Based on the description, an attacker who supplies a malicious file is likely able to trigger the flaw and potentially achieve arbitrary code execution.
OpenCVE Enrichment