
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5496 is a type confusion vulnerability in Labcenter Electronics Proteus that allows remote attackers to execute arbitrary code by tricking a user into opening a malicious PDSPRJ project file or visiting a malicious page. The flaw affects Proteus version 8.17 SP5, which the vendor confirmed is no longer in production as of October 2025. The vulnerability was reported to the vendor on April 14, 2025, and publicly disclosed as a zero-day advisory on April 6, 2026, after the vendor failed to issue a patch. It carries a CVSS v3.0 base score of 7.8 (High) (ZDI Advisory, GitHub Advisory).
The root cause is classified as CWE-843 (Access of Resource Using Incompatible Type — 'Type Confusion'), arising from insufficient validation of user-supplied data during the parsing of PDSPRJ project files in Labcenter Electronics Proteus. When a specially crafted PDSPRJ file is processed, the application accesses a resource using a type incompatible with the one used during allocation or initialization, leading to memory corruption that can be leveraged for arbitrary code execution. Exploitation requires local file access and user interaction — the target must open a malicious file or visit a page that triggers the file parsing. The vulnerability was discovered by researcher Andrea Micalizzi (aka rgod) and tracked internally as ZDI-CAN-25717 (ZDI Advisory).
Successful exploitation allows an attacker to execute arbitrary code in the context of the Proteus process, granting them the same privileges as the user running the application. This results in high confidentiality, integrity, and availability impact — an attacker could read sensitive design files, modify project data, or crash the application. Because Proteus is an electronics design tool used in engineering environments, exploitation could expose proprietary circuit designs or serve as an initial foothold for lateral movement within an engineering workstation network (ZDI Advisory, GitHub Advisory).
No confirmed in-the-wild exploitation has been observed, and no functional proof-of-concept exploit code is publicly available — the ZDI advisory provides only abstract vulnerability details and mitigation guidance without reproduction steps or payloads. The EPSS score is approximately 0.046–0.055%, placing it in the 17th percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Because the affected product is end-of-life and no patch was issued by the vendor, the ZDI published this as a zero-day advisory (ZDI Advisory, GitHub Advisory).
cmd.exe, powershell.exe, curl.exe); Proteus process making unexpected network connections.No vendor patch exists for CVE-2026-5496, as Labcenter Electronics confirmed that Proteus 8.17 SP5 and its installer are no longer in production as of October 2025. The ZDI's recommended mitigation is to restrict interaction with the product entirely. Organizations still running Proteus 8.17 SP5 should plan immediate migration to a supported alternative EDA tool. In the interim, users should avoid opening PDSPRJ files from untrusted sources, implement application whitelisting to limit Proteus execution, and consider network isolation of engineering workstations running the software (ZDI Advisory, GitHub Advisory).
The vulnerability received limited but notable coverage given its zero-day status at time of disclosure. The ZDI published the advisory after an extended disclosure timeline in which the vendor failed to produce a patch, citing end-of-life status for the product. Security aggregators including VulDB, INCIBE-CERT, and Mastodon security accounts (e.g., @thehackerwire) noted the advisory shortly after publication (ZDI Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."