CVE-2025-59297 PUBLISHED

File Parsing Out-Of-Bounds Write Vulnerability in DIAScreen

Assigner: Deltaww
Reserved: 12.09.2025 Published: 03.10.2025 Updated: 07.10.2025

Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a malicious file, an attacker can leverage this vulnerability to execute code in the context of the current process.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N
CVSS Score: 6.8

Product Status

Vendor Delta Electronics
Product DIAScreen
Versions Default: unaffected
  • affected from 0 to 1.6.1 (excl.)

Solutions

Download and update to DIAScreen v1.6.1 or later

Credits

  • Natnael Samson working with Trend Micro Zero Day Initiative reporter
  • CISA coordinator

References

Problem Types

  • CWE-787 Out-Of-Bounds Write CWE

Impacts

  • CAPEC-100 Overflow Buffers