Executive brief
Labcenter Proteus 9, a software suite used for electronic design automation and circuit simulation, is affected by a memory vulnerability. An attacker could exploit this flaw to gain full control over the system where the software is installed, potentially leading to the theft of intellectual property or disruption of engineering operations. Exploitation requires a user to interact with a malicious file provided by the attacker.
Technical details
An out-of-bounds write vulnerability (CWE-787) exists in Labcenter Proteus 9.1_SP4_Build_42914. The flaw occurs when the application writes data past the end of an allocated memory buffer, likely during the parsing of project or design files. While the attack vector is local, it requires no special privileges, though it does necessitate user interaction (UI:A/UI:R) to open a malicious file. Successful exploitation allows an attacker to achieve arbitrary code execution in the context of the current process. The vendor has released version 9.2 SP0 to address this issue.
Affected products
- Labcenter Electronics Proteus 9 9.1_SP4_Build_42914
Timeline
- 2026-07-07: disclosed: Initial publication by CISA and NVD
- 2026-07-07: patched: Vendor recommends upgrading to version 9.2 SP0