CVE-2025-61863
7.8FUJI ELECTRIC CO., LTD. / Hakko Electronics Co., Ltd. · V-SFT
An out-of-bounds read vulnerability in the V-SFT software allows attackers to trigger information disclosure, system crashes, or arbitrary code execution via specially crafted files.
Executive summary
A critical out-of-bounds read vulnerability in Fuji Electric V-SFT v6.2.7.0 and earlier poses a significant risk of arbitrary code execution and system instability.
Vulnerability
This is an out-of-bounds read flaw (CWE-125) occurring within the VS6ComFile!CSaveData::delete_mem function. The vulnerability can be triggered by an unauthenticated user if they are coerced into opening a specially crafted V-SFT file.
Business impact
The potential for arbitrary code execution and system failure (ABEND) represents a severe threat to operational continuity and data integrity. With a CVSS score of 7.8, this vulnerability is categorized as High, reflecting the significant impact on system availability and the potential for unauthorized control over the affected workstation.
Remediation
Immediate Action: Update the V-SFT software to the latest version provided by the vendor to ensure the vulnerability is patched.
Proactive Monitoring: Monitor system logs for abnormal application termination events or unexpected file access patterns associated with V-SFT project files.
Compensating Controls: Restrict the opening of V-SFT files from untrusted or unknown sources and ensure that users operate with the minimum necessary privileges to reduce the potential impact of an exploit.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the potential for arbitrary code execution, this vulnerability should be prioritized for remediation within your software maintenance cycle. Administrators must verify their current version of V-SFT and apply the vendor-supplied security updates as soon as they are made available to mitigate the risk of system compromise.