vuln-advisoryregulatorNewsThe Broadside1 min read

CISA flags Proteus 9 memory flaws

The risk sits on engineering workstations that open untrusted Proteus files, making software inventory the first useful control.


TL;DR

CISA published an ICS advisory for three high-severity memory-corruption vulnerabilities in Labcenter Proteus 9.1_SP4_Build_42914: CVE-2026-42953, CVE-2026-49033 and CVE-2026-42958. Successful exploitation could allow arbitrary code execution or information disclosure. Labcenter recommends updating to Proteus 9.2 SP0. CISA says the flaws are not remotely exploitable and has no reports of public exploitation, but defense-industrial-base and other critical-infrastructure users still need to find affected engineering workstations.

CISA’s advisory is a straightforward patch item: Labcenter Proteus 9.1_SP4_Build_42914 has three memory-corruption vulnerabilities, covering out-of-bounds write, stack-based buffer overflow and use-after-free conditions, and Labcenter’s fix is Proteus 9.2 SP0. The affected product is deployed worldwide across sectors including communications, critical manufacturing, the Defense Industrial Base, energy, healthcare, transportation, and water and wastewater.

The operational detail matters more than the acronym stack. CISA says the vulnerabilities are not exploitable remotely and has not seen known public exploitation. The likely exposure is an engineering workstation opening a malicious or specially crafted Proteus file, with code execution in the current process if exploitation succeeds. Contractors and independent software vendors using Proteus in design or simulation workflows should confirm installed versions, apply 9.2 SP0, and treat untrusted project files as the delivery path until the affected build is gone.


Published ·Deep Fathom