Impact
DASYLab suffers from an out‑of‑bounds write when parsing a .DSB file that contains improperly validated user data. An attacker must get a user to open a specifically crafted .DSB file, after which the memory corruption can be leveraged to execute arbitrary code with the privileges of the application. The high severity CVSS score of 8.5 indicates that a successful exploitation would result in a full compromise of the affected system.
Affected Systems
The vulnerability affects every version of measX DASYLab released prior to 2026.0.0. Users running older builds should identify their DASYLab version immediately. Industrial or laboratory environments using legacy DASYLab installations are at particular risk because they may be exposed to untrusted .DSB files via network shares, emails, or removable media.
Risk and Exploitability
With a CVSS score of 8.5, the risk of impact is high, yet the EPSS score is not available, implying uncertainty about current exploitation activity. The vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation yet. The likely attack vector requires user interaction to open a malicious .DSB file; however, if an attacker can influence which files are opened or can embed the payload into a trusted file, the code‑execution risk remains significant.
OpenCVE Enrichment