CVE-2025-61692
7.8KEYENCE CORPORATION · VT STUDIO
A use after free vulnerability in KEYENCE VT STUDIO versions 8.53 and prior allows for arbitrary code execution via specially crafted files.
Executive summary
A critical use after free vulnerability in KEYENCE VT STUDIO could allow an attacker to execute arbitrary code on the host system through the processing of a malicious file.
Vulnerability
The software contains a use after free vulnerability, identified as CWE-416, which can be triggered when the application parses a specially crafted file. Based on the CVSS vector, this requires user interaction and local access but does not require prior authentication.
Business impact
Successful exploitation of this vulnerability allows an attacker to achieve arbitrary code execution, which could lead to full system compromise. Given the CVSS score of 7.8, this represents a high risk to business operations, as it may facilitate data theft, unauthorized lateral movement, or the disruption of industrial automation processes managed by the software.
Remediation
Immediate Action: Users should immediately refer to the official KEYENCE security advisory at https://www.keyence.com/vt_vulnerability250930 to identify if a patch is available for their specific build and apply it without delay.
Proactive Monitoring: Security teams should monitor endpoint logs for unexpected process execution or application crashes occurring during file import or project loading operations.
Compensating Controls: Restrict the ability of the VT STUDIO application to open files from untrusted or external sources, and employ endpoint detection and response tools to flag suspicious file-parsing activities.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
This vulnerability presents a significant risk to the integrity and availability of systems utilizing KEYENCE VT STUDIO. Administrators must prioritize verifying their software versions against the vendor provided documentation and apply all recommended updates to prevent potential exploitation.