Description
The application contains a use-after-free vulnerability that can be exploited to cause memory corruption while parsing specially crafted files. This could allow an attacker to execute arbitrary code in the context of the current process.
Published: 2026-07-07
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a use‑after‑free flaw that corrupts memory while parsing crafted files, potentially allowing an attacker to execute arbitrary code within the process context of Proteus. It is classified as a CWE‑416 weakness and could be exploited to gain full system compromise if malicious input is supplied.

Affected Systems

The flaw affects Labcenter Proteus software versions prior to 9.2 SPO. Users running earlier releases are susceptible to this issue.

Risk and Exploitability

The CVSS score of 8.4 indicates a high severity, but the EPSS score of less than 1% suggests a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog, implying no known public exploits. Based on the description, an attacker who supplies a malicious file is likely able to trigger the flaw and potentially achieve arbitrary code execution.

Generated by OpenCVE AI on July 26, 2026 at 18:51 UTC.

Remediation

Vendor Solution

Labcenter recommends ensuring you are using the latest version (9.2 SPO) of the software. Version can be found by looking at the bottom left of the Proteus home page (Version 8 or higher) or by selecting the About ISIS or About ARES option from the Help menu. Update notifications appear in the new and information section of the home page where you can activate the download and installation directly. If you have questions or need help please contact Labcenter or your local distributor.


OpenCVE Recommended Actions

  • Apply Labcenter’s latest update (version 9.2 SPO) following the vendor’s official instructions.
  • Restrict file import operations to trusted users and enforce strict file type validation within Proteus.
  • If an update cannot be applied immediately, isolate the Proteus installation on a restricted external file access environment to mitigate exploitation risk.

Generated by OpenCVE AI on July 26, 2026 at 18:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 08 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Labcenter
Labcenter proteus
Vendors & Products Labcenter
Labcenter proteus

Tue, 07 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Description The application contains a use-after-free vulnerability that can be exploited to cause memory corruption while parsing specially crafted files. This could allow an attacker to execute arbitrary code in the context of the current process.
Title Use After Free in Labcenter Proteus
Weaknesses CWE-416
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Labcenter Proteus
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-07-08T13:05:45.177Z

Reserved: 2026-06-03T15:40:50.731Z

Link: CVE-2026-42958

cve-icon Vulnrichment

Updated: 2026-07-08T13:05:23.289Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T19:00:02Z

Weaknesses