Junglewise Threat Intelligence

CVE-2026-5495: Labcenter Electronics Proteus out-of-bounds write in PDSPRJ parsing

CVE-2026-5495 · Severity: high · CVSS 7.8 · Published 2026-04-11

Technologies: Labcenter Proteus. Vendors: Labcenter.

Executive brief

Labcenter Electronics Proteus, a software suite used for electronic design automation and circuit simulation, contains a vulnerability in how it handles project files. An attacker could trick a user into opening a specially crafted project file, allowing the attacker to take control of the user's computer and execute malicious software. This could lead to the theft of intellectual property, data loss, or unauthorized access to the corporate network.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in Labcenter Electronics Proteus during the parsing of PDSPRJ files. The root cause is a lack of proper validation of user-supplied data within the file structure, leading to a write operation past the end of an allocated buffer. While the attack vector is categorized as local because it requires the user to open a file, it effectively allows remote code execution in the context of the current process if a victim is enticed to open a malicious project file or visit a malicious page. The vendor has indicated the software is no longer in production, and no official patch is available; users are advised to restrict interaction with the product.

Affected products

  • Labcenter Electronics Proteus 8.17 SP5

Timeline

  • 2025-04-14: disclosed: Vulnerability reported to vendor by ZDI
  • 2026-04-06: advisory: ZDI published zero-day advisory
  • 2026-04-11: other: CVE published to NVD

References

Related threats