Junglewise Threat Intelligence

CVE-2026-5496: Labcenter Electronics Proteus type confusion in PDSPRJ parsing

CVE-2026-5496 · Severity: high · CVSS 7.8 · Published 2026-04-11

Technologies: Labcenter Proteus. Vendors: Labcenter.

Executive brief

Labcenter Electronics Proteus, a software suite used for electronic design automation and circuit simulation, contains a vulnerability in how it handles project files. An attacker can exploit this by tricking a user into opening a specially crafted PDSPRJ file, which could allow the attacker to take control of the user's computer. This could lead to the theft of sensitive design data or the installation of malicious software.

Technical details

A type confusion vulnerability (CWE-843) exists within the PDSPRJ file parsing engine of Labcenter Electronics Proteus. The flaw stems from insufficient validation of user-supplied data within the project file structure, allowing an attacker to force the application to interpret data as an incompatible type. While categorized as a remote code execution vulnerability, the attack vector is local/user-interaction-dependent, requiring a target to open a crafted file or visit a malicious page. Successful exploitation allows for arbitrary code execution in the context of the process. The vendor has indicated the affected version is no longer in production, and no official patch is available.

Affected products

  • Labcenter Electronics Proteus 8.17 SP5

Timeline

  • 2025-04-14: disclosed: Vulnerability reported to vendor
  • 2025-10-16: other: Vendor stated software is no longer in production
  • 2026-04-06: advisory: ZDI published zero-day advisory
  • 2026-04-11: disclosed: CVE published to NVD

References

Related threats