Executive brief
DASYLab is data acquisition and signal analysis software used in testing and measurement applications. The software contains multiple out-of-bounds write vulnerabilities when parsing specially crafted DSB project files, which could allow an attacker to execute arbitrary code if a user opens a malicious file. Exploitation requires user interaction (opening a malicious file) and cannot occur remotely.
Technical details
These are out-of-bounds write vulnerabilities (CWE-787) in DASYLab's DSB file parser caused by improper validation of user-supplied data in file structures. The vulnerabilities result in heap buffer overflows when parsing specially crafted DSB files. Attack requires local delivery of a malicious DSB file and user interaction to open it; the vulnerabilities are not remotely exploitable. Successful exploitation allows arbitrary code execution in the context of the affected application. The vulnerabilities affect all DASYLab versions before 2026.0.0 (Build 65) and are resolved in that version and later.
Affected products
- measX DASYLab before 2026.0.0 (Build 65)
Timeline
- 2026-08-17: disclosed
- 2026-09-03: patched: Fixed in DASYLab 2026.0.0 (Build 65)
- 2026-09-03: advisory