Description
There is an out-of-bounds write vulnerability in DASYLab due to lack of proper validation of user-supplied data. Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file.  This issue affects all versions before 2026.0.0.
Published: 2026-09-03
Score: 8.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

DASYLab suffers from an out‑of‑bounds write when parsing a .DSB file that contains improperly validated user data. An attacker must get a user to open a specifically crafted .DSB file, after which the memory corruption can be leveraged to execute arbitrary code with the privileges of the application. The high severity CVSS score of 8.5 indicates that a successful exploitation would result in a full compromise of the affected system.

Affected Systems

The vulnerability affects every version of measX DASYLab released prior to 2026.0.0. Users running older builds should identify their DASYLab version immediately. Industrial or laboratory environments using legacy DASYLab installations are at particular risk because they may be exposed to untrusted .DSB files via network shares, emails, or removable media.

Risk and Exploitability

With a CVSS score of 8.5, the risk of impact is high, yet the EPSS score is not available, implying uncertainty about current exploitation activity. The vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation yet. The likely attack vector requires user interaction to open a malicious .DSB file; however, if an attacker can influence which files are opened or can embed the payload into a trusted file, the code‑execution risk remains significant.

Generated by OpenCVE AI on September 4, 2026 at 00:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor patch (addresses the Out-of-Bounds Write flaw identified as CWE-787).
  • Restrict the acceptance of .DSB files to trusted sources, disabling automatic opening of files from external shares or unknown parties to reduce the risk of CWE-787 exploitation.
  • Employ application whitelisting or file‑integrity monitoring to detect and block malformed .DSB files before they are processed, mitigating the CWE-787 vulnerability.

Generated by OpenCVE AI on September 4, 2026 at 00:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description There is an out-of-bounds write vulnerability in DASYLab due to lack of proper validation of user-supplied data. Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file.  This issue affects all versions before 2026.0.0.
Title Out Of Bounds Write parsing a .DSB file in DASYLab due to lack of proper validation of user-supplied data
First Time appeared Measx
Measx dasylab
Weaknesses CWE-787
CPEs cpe:2.3:a:measx:dasylab:*:*:*:*:*:*:*:*
Vendors & Products Measx
Measx dasylab
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: NI

Published:

Updated: 2026-09-03T21:43:48.330Z

Reserved: 2026-07-19T15:12:06.825Z

Link: CVE-2026-64195

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-03T22:18:09.293

Modified: 2026-09-03T22:18:09.293

Link: CVE-2026-64195

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T00:15:07Z

Weaknesses