Description
There is an out-of-bounds write vulnerability in DASYLab due to improper validation of user-supplied data, resulting in a write past the end of an allocated data structure. Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file.  This issue affects all versions before 2026.0.0.
Published: 2026-09-03
Score: 8.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw that allows an out‑of‑bounds write occurs in DASYLab when it processes user‑supplied .DSB files. The vulnerability permits data to be written past the allocated memory buffer, which could corrupt internal structures or place malicious code in memory. If exploited, an attacker could potentially alter the integrity or availability of the application, or execute arbitrary code on the host.

Affected Systems

MeasX DASYLab is affected. All releases before version 2026.0.0 contain the vulnerability.

Risk and Exploitability

Based on the description, it is inferred that the attacker must trick a user into opening a specially crafted .DSB file, providing a user‑initiated local file execution vector. The CVSS score of 8.5 indicates high severity. EPSS information is not available, and the flaw is not listed in the CISA KEV catalog. Consequently, the risk is significant for environments where users may unknowingly open malicious files.

Generated by OpenCVE AI on September 4, 2026 at 00:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to DASYLab version 2026.0.0 or later to apply the vendor fix.
  • Avoid opening .DSB files from untrusted or unknown sources until the patch is installed.
  • Use file‑ingestion controls or sandboxing to restrict execution of external .DSB files while the vulnerability remains unresolved.

Generated by OpenCVE AI on September 4, 2026 at 00:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description There is an out-of-bounds write vulnerability in DASYLab due to improper validation of user-supplied data, resulting in a write past the end of an allocated data structure. Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file.  This issue affects all versions before 2026.0.0.
Title Out Of Bounds Write when parsing a .DSB file in DASYLab due to improper validation of user-supplied data, resulting in a write past the end of an allocated data structure
First Time appeared Measx
Measx dasylab
Weaknesses CWE-787
CPEs cpe:2.3:a:measx:dasylab:*:*:*:*:*:*:*:*
Vendors & Products Measx
Measx dasylab
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: NI

Published:

Updated: 2026-09-03T21:49:18.605Z

Reserved: 2026-07-19T15:12:06.825Z

Link: CVE-2026-64197

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-03T22:18:10.073

Modified: 2026-09-03T22:18:10.073

Link: CVE-2026-64197

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T01:45:04Z

Weaknesses