OVERVIEW CVE-2026-5493 is a remote code execution vulnerability in Labcenter Electronics Proteus affecting the application's PDSPRJ file parser. An out-of-bounds write flaw exists due to insufficient validation of user-supplied data during file parsing, enabling attackers to execute arbitrary code on affected systems. The vulnerability requires user interaction, as targets must open a malicious PDSPRJ file or visit a malicious webpage hosting such a file. SEVERITY The vulnerability carries a CVSS score of 7.8 (HIGH) with a local attack vector, requiring no privileges and user interaction. The flaw provides high impact across confidentiality, integrity, and availability, allowing code execution in the current process context. The EPSS score of 0.000630000 indicates limited real-world exploitation activity relative to the broader CVE landscape. EXPLOITATION STATUS There is no current evidence of active exploitation. The vulnerability is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog and remains inactive on threat tracking lists. While the FAUCET risk score of 49.0/100 suggests moderate concern, the low EPSS score and lack of public exploitation reports indicate this is not currently being weaponized in the wild. No public exploit code availability has been reported.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.17CPE matchmatch criteria | cpe:2.3:a:labcenter:proteus:8.17:sp5:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.