CVE-2025-61859
7.8FUJI ELECTRIC CO., LTD. / Hakko Electronics Co., Ltd. · V-SFT
An out-of-bounds write vulnerability in V-SFT allows attackers to trigger an abnormal system end or achieve arbitrary code execution via specially crafted files.
Executive summary
A critical out-of-bounds write vulnerability in Fuji Electric V-SFT software presents a significant risk of arbitrary code execution and system failure.
Vulnerability
The software contains an out-of-bounds write flaw in the VS6ComFile!CItemDraw::is_motion_tween component, which can be triggered by processing a malicious file. This vulnerability does not require prior authentication but necessitates user interaction to open the crafted file.
Business impact
The vulnerability carries a CVSS score of 7.8, indicating a high severity risk to operational integrity. Successful exploitation allows an attacker to execute arbitrary code with the privileges of the user running the application, potentially leading to full system compromise, data loss, or significant operational downtime for industrial control environments.
Remediation
Immediate Action: Users should immediately transition to the latest available version of V-SFT as provided by the vendor, or cease use of the software if updates are not yet available.
Proactive Monitoring: Security teams should monitor workstation and server logs for abnormal application crashes or unexpected file access patterns associated with the V-SFT software.
Compensating Controls: Organizations should implement strict application control policies to prevent the execution of untrusted or unauthorized V-SFT project files from external or unknown sources.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the potential for arbitrary code execution, this vulnerability poses a severe threat to systems utilizing V-SFT. Administrators must prioritize updating to the latest secure version once released by Fuji Electric. Until then, enforce strict file handling procedures and restrict the opening of project files from unverified or untrusted sources to mitigate the risk of exploitation.