V-SFT Out-of-Bounds Write Vulnerability in VS6EditData MacroCommandCheck Function Allowing Arbitrary Code Execution

Vulnerability

A vulnerability exists in V-SFT versions through 6.2.5.0, specifically within the VS6EditData.dll file. The issue involves an out-of-bounds write in the MacroCommandCheck function, which can be triggered by opening specially crafted V7 or V8 files. This vulnerability may lead to a crash, unauthorized information disclosure, and arbitrary code execution.

Impact

Exploitation of this vulnerability can cause the application to crash, disclose sensitive information, and execute arbitrary code on the affected system.

Remediation

Users are advised to update to V-SFT version 6.2.6.0 or later, where this vulnerability has been addressed.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
4.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.