CVE-2025-61864

7.8

FUJI ELECTRIC CO., LTD. / Hakko Electronics Co., Ltd. · V-SFT

A use after free vulnerability in V-SFT v6.2.7.0 and earlier allows attackers to trigger arbitrary code execution or system crashes by opening malicious files.

Executive summary

A critical use after free vulnerability in Fuji Electric V-SFT software could allow an attacker to achieve arbitrary code execution via a specially crafted file.

Vulnerability

The software contains a use after free flaw in the VS6ComFile!load_link_inf function. The vulnerability is triggered when an unauthenticated user opens a specially crafted V-SFT file, potentially leading to arbitrary code execution or an abnormal application termination.

Business impact

This vulnerability poses a significant risk to operational integrity, as successful exploitation results in total impact to system availability and integrity. Given the CVSS score of 7.8, the potential for arbitrary code execution necessitates immediate attention, particularly in industrial environments where V-SFT is used to manage HMI configurations. Unauthorized code execution could lead to the compromise of proprietary configuration data or unauthorized control over connected industrial hardware.

Remediation

Immediate Action: Users should restrict the opening of untrusted or external V-SFT project files and verify the integrity of files before processing. Monitor the vendor advisory portal for the release of a corrective patch.

Proactive Monitoring: Security teams should monitor system logs for abnormal application crashes or unexpected memory access errors associated with V-SFT processes.

Compensating Controls: Deploy endpoint protection solutions capable of scanning incoming files for malicious patterns and enforce strict file access controls to limit the execution of unrecognized project files.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Due to the severity of the potential impact, administrators should treat this vulnerability with high urgency. Until a vendor-supplied patch is available, organizations must implement strict file handling policies to prevent the opening of suspicious project files. Continuous monitoring of the Fuji Electric support portal is required to ensure the patch is applied as soon as it becomes available.

More FUJI ELECTRIC CO., LTD. / Hakko Electronics Co., Ltd. CVEs

Sources