CVE-2025-61691
7.8KEYENCE CORPORATION · VT STUDIO
KEYENCE VT STUDIO versions 8.53 and prior are vulnerable to an out-of-bounds read flaw that can lead to arbitrary code execution when processing a specially crafted file.
Executive summary
A critical out-of-bounds read vulnerability in KEYENCE VT STUDIO allows for potential arbitrary code execution, posing a severe risk to industrial control environments.
Vulnerability
This is an out-of-bounds read vulnerability (CWE-125) triggered when the software processes a specially crafted file. The vulnerability does not require authentication and can be exploited by an unprivileged attacker, though it requires user interaction to open the malicious file.
Business impact
The ability to achieve arbitrary code execution on systems running VT STUDIO could allow an attacker to gain full control over the application, leading to unauthorized data access, process disruption, or potential pivot points into broader industrial networks. Given the CVSS score of 7.8, this vulnerability represents a high risk to operational continuity and system integrity. Successful exploitation could result in significant downtime and compromise of sensitive manufacturing configurations.
Remediation
Immediate Action: Users should immediately review the official KEYENCE security advisory at https://www.keyence.com/vt_vulnerability250930 to identify if a specific patch or version update is available for their deployment.
Proactive Monitoring: Security teams should monitor workstation and server logs for abnormal application crashes or unauthorized file access patterns related to VT STUDIO processes.
Compensating Controls: Restrict the ability of VT STUDIO to open files from untrusted sources and utilize endpoint detection and response tools to monitor for suspicious child processes spawned by the application.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability presents a significant risk to industrial software environments and should be treated with high priority. Organizations must verify their current version of VT STUDIO against the vendor's guidance and apply updates as soon as they are made available by KEYENCE. Until an update is applied, maintain strict file handling policies to ensure that only trusted, verified project files are processed by the software.