Executive brief
LS Electric GMWin 4 is a programming software tool used for industrial control systems. A vulnerability in how the software handles project files (PRJ) could allow an attacker to execute malicious code or access sensitive information if a user is tricked into opening a specially crafted file. Because this product has been discontinued, users are encouraged to migrate to supported hardware series to maintain security.
Technical details
An out-of-bounds write vulnerability (CWE-787) exists in LS Electric GMWin 4 version 4.18 during the parsing of PRJ files. The issue stems from insufficient validation of user-supplied data within the file structure, leading to memory corruption. An attacker can exploit this by convincing a user to open a crafted PRJ file, potentially resulting in information disclosure or arbitrary code execution. The attack requires local access and user interaction. As the product is discontinued, no patch is available; the vendor recommends migrating to the XGT series.
Affected products
- LS Electric GMWin 4 4.18
Timeline
- 2025-06-17: advisory: Initial publication by CISA (ICSA-25-168-02)
- 2025-06-17: disclosed