Out-of-Bounds Read in DASYLab by MeasX
CVE-2026-64200
8.5HIGH
What is CVE-2026-64200?
An out-of-bounds read vulnerability exists in DASYLab due to insufficient validation of user-supplied data. This issue allows an attacker to read beyond the allocated heap buffer during string conversion, potentially exposing sensitive information. To exploit this vulnerability, an attacker must convince a user to open a specially crafted .DSB file, which could lead to unauthorized data access. It's crucial for users to update their software to the latest version, which addresses this security concern.
Affected Version(s)
DASYLab 0 < 2026.0.0
References
CVSS V4
Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
measX credits Michael Heinzl for reporting these issues and coordinating disclosure.
