Out-of-Bounds Read in DASYLab by MeasX
CVE-2026-64200

8.5HIGH

Key Information:

Vendor

Measx

Status
Vendor
CVE Published:
3 September 2026

What is CVE-2026-64200?

An out-of-bounds read vulnerability exists in DASYLab due to insufficient validation of user-supplied data. This issue allows an attacker to read beyond the allocated heap buffer during string conversion, potentially exposing sensitive information. To exploit this vulnerability, an attacker must convince a user to open a specially crafted .DSB file, which could lead to unauthorized data access. It's crucial for users to update their software to the latest version, which addresses this security concern.

Affected Version(s)

DASYLab 0 < 2026.0.0

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

measX credits Michael Heinzl for reporting these issues and coordinating disclosure.
.