Stack-Based Buffer Overflow in Cytel Studio Affects Multiple Versions
CVE-2011-10015
Key Information:
- Vendor
Cytel Inc.
- Status
- Vendor
- CVE Published:
- 13 August 2025
Badges
What is CVE-2011-10015?
Cytel Studio, specifically version 9.0 and earlier, is vulnerable to a stack-based buffer overflow that can be exploited by opening a specially crafted .CY3 file. This vulnerability arises from the application's failure to perform proper bounds checking when copying user-controlled strings into a fixed-size stack buffer of 256 bytes. Successful exploitation can lead to arbitrary code execution, potentially allowing an attacker to gain control of the affected system.
Affected Version(s)
Studio * <= 9.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved