Executive brief
Raptor is a project design and simulation tool used by industrial automation engineers. A double-free memory vulnerability allows an attacker to corrupt the application heap and potentially crash the program or execute arbitrary code by tricking a user into importing a specially crafted malicious project file (SSD format).
Technical details
A CWE-415 double-free vulnerability exists in Raptor's SSD file parser. When processing a malicious SSD project file, the application attempts to free the same memory region twice, causing heap metadata corruption. The vulnerability requires user interaction (importing a file) and is triggered via a network/local file source. Successful exploitation could result in denial of service through application crash or potentially arbitrary code execution depending on heap layout and exploitation sophistication. A patch is expected from Schneider Electric via their security advisory SEVD-2026-013-04.
Affected products
- Schneider Electric Raptor <UNKNOWN>
Timeline
- 2026-01-15: disclosed
- 2026-01-15: advisory: SEVD-2026-013-04