Description
There is an out-of-bounds write vulnerability in DASYLab due to improper validation of user-supplied data, resulting in a write past the end of an allocated heap. Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file.  This issue affects all versions before 2026.0.0.
Published: 2026-09-03
Score: 8.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is an out‑of‑bounds write that occurs when DASYLab parses a user‑supplied .DSB file. The error allows the application to write beyond the end of an allocated heap buffer, which can lead to arbitrary code execution or system compromise. It is a classic buffer overflow flaw (CWE‑787).

Affected Systems

The issue affects all versions of measX DASYLab prior to 2026.0.0. Users running any earlier release are vulnerable, regardless of operating system or installation environment.

Risk and Exploitability

With a CVSS score of 8.5 this vulnerability is considered high severity. The EPSS score is not available, but the lack of a KEV listing indicates no publicly known active exploit deployments at present. Exploitation requires local user interaction and the opening of a malicious .DSB file, making social‑engineering or targeted delivery the most likely attack paths.

Generated by OpenCVE AI on September 3, 2026 at 23:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the DASYLab 2026.0.0 or later build provided by measX to eliminate the buffer‑overflow flaw.
  • Restrict or quarantine .DSB files from untrusted or unknown sources so that users cannot inadvertently open malicious files.
  • Use endpoint protection or malware scanners to detect and block known malicious .DSB payloads before they reach the application.

Generated by OpenCVE AI on September 3, 2026 at 23:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description There is an out-of-bounds write vulnerability in DASYLab due to improper validation of user-supplied data, resulting in a write past the end of an allocated heap. Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file.  This issue affects all versions before 2026.0.0.
Title Out Of Bounds Write when parsing a .DSB file in DASYLab due to improper validation of user-supplied data, resulting in a write past the end of an allocated heap
First Time appeared Measx
Measx dasylab
Weaknesses CWE-787
CPEs cpe:2.3:a:measx:dasylab:*:*:*:*:*:*:*:*
Vendors & Products Measx
Measx dasylab
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: NI

Published:

Updated: 2026-09-03T21:46:51.568Z

Reserved: 2026-07-19T15:12:06.825Z

Link: CVE-2026-64196

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-03T22:18:09.950

Modified: 2026-09-03T22:18:09.950

Link: CVE-2026-64196

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T00:15:06Z

Weaknesses