Executive brief
Labcenter Proteus 9, a suite of software tools used for electronic design automation and circuit simulation, is affected by a memory corruption vulnerability. An attacker could exploit this by tricking a user into opening a specially crafted file, potentially allowing the attacker to take control of the computer or disrupt engineering operations. This could lead to the theft of intellectual property or unauthorized changes to critical hardware designs.
Technical details
A use-after-free (UAF) vulnerability exists in Labcenter Proteus 9 (specifically version 9.1_SP4_Build_42914) within its file parsing logic. The flaw is triggered when the application attempts to access memory that has already been deallocated during the processing of a maliciously crafted project or design file. This is a local attack vector requiring user interaction (opening a file). Successful exploitation can lead to memory corruption and arbitrary code execution in the context of the current process. The vendor recommends upgrading to version 9.2 SP0 to remediate the issue.
Affected products
- Labcenter Electronics Proteus 9 9.1_SP4_Build_42914
Timeline
- 2026-07-07: advisory: CISA and NVD published the advisory (ICSA-26-188-06)
- 2026-07-07: disclosed