Labcenter Proteus 9
Summary
Successful exploitation of these vulnerabilities could disclose information and allow a malicious user to execute arbitrary code on affected installations.
The following versions of Labcenter Proteus 9 are affected:
- Proteus 9.1_SP4_Build_42914
| CVSS | Vendor | Equipment | Vulnerabilities |
|---|---|---|---|
| v3 7.8 | Labcenter Electronics | Labcenter Proteus 9 | Out-of-bounds Write, Stack-based Buffer Overflow, Use After Free |
Background
- Critical Infrastructure Sectors: Communications, Critical Manufacturing, Defense Industrial Base, Energy, Healthcare and Public Health, Transportation Systems, Water and Wastewater
- Countries/Areas Deployed: Worldwide
- Company Headquarters Location: United Kingdom
Vulnerabilities
CVE-2026-42953
The application contains an out-of-bounds write vulnerability that can be exploited by an attacker to cause the program to write data past the end of an allocated memory buffer. This can lead to arbitrary code execution.
Affected Products
Labcenter Proteus 9
Labcenter Electronics
Labcenter Electronics Proteus: 9.1_SP4_Build_42914
known_affected
Remediations
Vendor fix
Labcenter recommends ensuring you are using the latest version (9.2 SPO) of the software. Version can be found by looking at the bottom left of the Proteus home page (Version 8 or higher) or by selecting the About ISIS or About ARES option from the Help menu. Update notifications appear in the new and information section of the home page where you can activate the download and installation directly.
Mitigation
If you have questions or need help please contact Labcenter or your local distributor.
Relevant CWE: CWE-787 Out-of-bounds Write
Metrics
| CVSS Version | Base Score | Base Severity | Vector String |
|---|---|---|---|
| 3.1 | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| 4.0 | 8.4 | HIGH | CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |



