Impact
A flaw that allows an out‑of‑bounds write occurs in DASYLab when it processes user‑supplied .DSB files. The vulnerability permits data to be written past the allocated memory buffer, which could corrupt internal structures or place malicious code in memory. If exploited, an attacker could potentially alter the integrity or availability of the application, or execute arbitrary code on the host.
Affected Systems
MeasX DASYLab is affected. All releases before version 2026.0.0 contain the vulnerability.
Risk and Exploitability
Based on the description, it is inferred that the attacker must trick a user into opening a specially crafted .DSB file, providing a user‑initiated local file execution vector. The CVSS score of 8.5 indicates high severity. EPSS information is not available, and the flaw is not listed in the CISA KEV catalog. Consequently, the risk is significant for environments where users may unknowingly open malicious files.
OpenCVE Enrichment