Executive brief
Labcenter Electronics Proteus, a software suite used for electronic design automation and circuit simulation, is vulnerable to a security flaw when opening specially crafted project files. If a user is tricked into opening a malicious PDSPRJ file, an attacker could gain the ability to run unauthorized commands on the user's computer. This could lead to the theft of sensitive design data, full system compromise, or disruption of engineering operations.
Technical details
An out-of-bounds write vulnerability (CWE-787) exists in Labcenter Electronics Proteus during the parsing of PDSPRJ project files. The root cause is a lack of proper validation of user-supplied data within the file, allowing a write operation to exceed the boundaries of an allocated buffer. Although categorized as local attack vector (AV:L) because it requires opening a file, it effectively allows remote code execution if an attacker can deliver the file via social engineering or a malicious website. The exploit runs in the context of the current process. The vendor has indicated the product is no longer in production, and no official patch is available; users are advised to restrict interaction with untrusted PDSPRJ files.
Affected products
- Labcenter Electronics Proteus 8.17 SP5
Timeline
- 2025-04-14: other: Vulnerability reported to vendor
- 2026-04-06: advisory: Coordinated public release of advisory by ZDI
- 2026-04-11: disclosed: NVD publication date