CVE-2026-12578 PUBLISHED

DTMSoft - Deserialization of Untrusted Data Vulnerability

Assigner: Deltaww
Reserved: 18.06.2026 Published: 30.06.2026 Updated: 30.06.2026

The affected product is vulnerable to a deserialization of untrusted data, which may allow an attacker to execute arbitrary code.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.4

Product Status

Vendor deltaww
Product DTMSoft
Versions Default: unaffected
  • Version * is affected

Workarounds

Users are recommended to take the following mitigation measures:

  • Do not open unsolicited project files: Do not open or import unsolicited project files, untrusted Internet links, or unexpected attachments from emails, network shares, or USB drives. Always verify the source of the file before opening it.

  • Avoid running as administrator: Do not use the "Run as Administrator" option when launching the software. Running the software with standard user privileges effectively limits the damage of potential malicious code.

Credits

  • CISA coordinator
  • kimiya working with Trend Micro Zero Day Initiative reporter

References

Problem Types

  • CWE-502 Deserialization of untrusted data CWE

Impacts

  • CAPEC-586 Object Injection