Out-of-Bounds Read Vulnerability in DASYLab by MeasX
CVE-2026-64198

8.5HIGH

Key Information:

Vendor

Measx

Status
Vendor
CVE Published:
3 September 2026

What is CVE-2026-64198?

DASYLab, a data acquisition software developed by MeasX, is susceptible to an out-of-bounds read vulnerability due to insufficient validation of user-supplied data. This flaw allows attackers to read memory beyond allocated boundaries, which occurs during the handling of specially crafted .DSB files. Exploitation requires social engineering, convincing a user to open the malicious file, potentially leading to unauthorized data access.

Affected Version(s)

DASYLab 0 < 2026.0.0

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

measX credits Michael Heinzl for reporting these issues and coordinating disclosure.
.