CVE-2025-9188

7.8

Digilent · DASYLab

Digilent DASYLab contains a deserialization of untrusted data vulnerability that allows for arbitrary code execution via a specially crafted DSB file.

Executive summary

A critical deserialization vulnerability in Digilent DASYLab could allow an attacker to achieve arbitrary code execution by tricking a user into opening a malicious DSB file.

Vulnerability

This vulnerability involves the insecure deserialization of untrusted data (CWE-502). Successful exploitation requires local user interaction, where an attacker must convince a victim to open a specially crafted DSB file, leading to potential arbitrary code execution.

Business impact

The ability to execute arbitrary code on a user machine poses a significant risk to organizational integrity and data confidentiality. Given the CVSS score of 7.8, this vulnerability is classified as High severity. An attacker could leverage this flaw to install malware, exfiltrate sensitive engineering data, or gain a foothold within the corporate network, leading to potential system compromise and operational disruption.

Remediation

Immediate Action: Users should exercise caution and avoid opening DSB files from untrusted or unknown sources until a vendor-provided security patch is released and applied.

Proactive Monitoring: Security teams should monitor endpoint activity for unusual process execution patterns initiated by the DASYLab application.

Compensating Controls: Deploy endpoint protection solutions to scan incoming files for malicious content and enforce application allowlisting policies to limit the execution of unauthorized code.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The severity of this flaw necessitates immediate attention. Organizations should monitor the provided vendor advisory link for the release of security updates. Until a patch is available, strictly control the intake of DSB files and restrict access to the application to authorized users only to minimize the attack surface.

Sources

Originally found and disclosed by kimiya working with Trend Micro Zero Day Initiative, per the CVE Program record.