V-SFT v6.2.5.0 and earlier contains an issue with out-of...
        
  High severity
        
          Unreviewed
      
        Published
          May 19, 2025 
          to the GitHub Advisory Database
          •
          Updated May 19, 2025 
      
  
Description
        Published by the National Vulnerability Database
      May 19, 2025 
    
  
        Published to the GitHub Advisory Database
      May 19, 2025 
    
  
        Last updated
      May 19, 2025 
    
  
V-SFT v6.2.5.0 and earlier contains an issue with out-of-bounds read in VS6EditData!VS4_SaveEnvFile function. Opening specially crafted V7 or V8 files may lead to crash, information disclosure, and arbitrary code execution.
References