CVE-2026-32928

7.8

Fuji Electric · V-SFT

A stack-based buffer overflow in V-SFT allows attackers to execute arbitrary code by enticing a user to open a specially crafted V7 file.

Executive summary

A critical stack-based buffer overflow vulnerability in Fuji Electric V-SFT software may allow for arbitrary code execution when processing malicious files.

Vulnerability

The application is susceptible to a stack-based buffer overflow within the VS6ComFile component, specifically in the CSaveData::_conv_AnimationItem function, which can be triggered by an unauthenticated user if they provide a crafted V7 file for processing.

Business impact

Successful exploitation of this vulnerability allows an attacker to achieve arbitrary code execution on the host machine. Given the CVSS score of 7.8, this represents a high-severity risk that could lead to full system compromise, loss of data integrity, and unauthorized control over the industrial automation software environment.

Remediation

Immediate Action: Update V-SFT to version 6.2.11.0 or later as specified in the official vendor advisory to resolve the buffer overflow condition.

Proactive Monitoring: Monitor workstation logs for unexpected application crashes related to the VS6ComFile module or unusual file access patterns during project loading.

Compensating Controls: Restrict the opening of untrusted or externally sourced V7 project files until the software has been patched.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

This vulnerability poses a significant risk to engineering and automation environments utilizing Fuji Electric V-SFT. System administrators must prioritize upgrading to the latest version to eliminate the buffer overflow risk. Ensure that all personnel are aware of the dangers associated with opening files from unverified or untrusted sources while the patching process is underway.

More Fuji Electric CVEs

Sources