CVE-2025-58776
7.8KEYENCE CORPORATION · KV STUDIO
KEYENCE CORPORATION KV STUDIO versions 12.23 and prior are vulnerable to a stack-based buffer overflow that may allow arbitrary code execution when processing a specially crafted file.
Executive summary
A stack-based buffer overflow in KEYENCE CORPORATION KV STUDIO versions 12.23 and prior poses a severe risk of arbitrary code execution through malicious file processing.
Vulnerability
This is a stack-based buffer overflow (CWE-121) occurring when the software parses specially crafted files. The vulnerability can be triggered without authentication by an attacker who convinces a user to open a malicious file (UI:A).
Business impact
Successful exploitation of this buffer overflow could allow an attacker to execute arbitrary code with the privileges of the application user. Given the CVSS score of 7.8, this represents a high-severity risk that could lead to full system compromise, unauthorized data access, or the disruption of industrial control configurations managed by the software.
Remediation
Immediate Action: Update KEYENCE CORPORATION KV STUDIO to the latest available version provided by the vendor to remediate the buffer overflow.
Proactive Monitoring: Monitor system logs for unexpected application crashes or anomalous behavior when opening project files.
Compensating Controls: Restrict the ability of users to open files from untrusted sources and utilize endpoint protection solutions to scan files for known malicious patterns before execution.
Exploitation status
Public Exploit Available: No (exploit_available: false).
Analyst recommendation
The severity of this vulnerability necessitates immediate action to update the affected software. Security teams should prioritize patching systems running KV STUDIO 12.23 or earlier to prevent potential code execution scenarios. Until an update is applied, exercise extreme caution when handling files from untrusted or external origins.