CVE-2025-49848
Out-of-bounds Write in LS Electric GMWin 4
CVSS Score
7.8
EPSS Score
0.1%
EPSS Percentile
32th
An out-of-bounds write vulnerability exists within the parsing of PRJ files. The issues result from the lack of proper validation of user-supplied data, which can result in different memory corruption issues within the application, such as reading and writing past the end of allocated data structures.
| CWE | CWE-787 |
| Vendor | ls electric |
| Product | gmwin 4 |
| Published | Jun 17, 2025 |
| Last Updated | Jun 4, 2026 |
Stay Ahead of the Next One
Get instant alerts for ls electric gmwin 4
Be the first to know when new high vulnerabilities affecting ls electric gmwin 4 are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
LS Electric / GMWin 4
Version 4.18
References
Credits
Michael Heinzl reported these vulnerabilities to CISA.