AI analysis
OriginLab OriginPro contains an out-of-bounds write vulnerability (CWE-787) in its parsing of OPJ project files, where insufficient validation of user-supplied data allows a write past the end of an allocated data structure. Exploitation requires user interaction: the target must open a malicious OPJ file or visit a page that delivers one. A successful attack lets the attacker execute arbitrary code in the context of the current process, i.e., with the privileges of the logged-in user running OriginPro (CVSS 3.0 score 7.8 High). Any user of affected OriginLab OriginPro builds is exposed whenever the application parses an attacker-supplied OPJ file. The flaw was disclosed via Trend Micro ZDI (ZDI-CAN-29332, ZDI-26-548); there is no public proof-of-concept, EPSS is 0.2%, and it is not in CISA KEV, so no exploitation is currently known.
What to do: Update OriginPro to the patched build referenced in ZDI-26-548 / OriginLab's advisory, as no fixed version number is included in this data. Until patched, do not open OPJ files from untrusted sources and caution users who routinely exchange Origin project files by email or download. With no public PoC, EPSS at 0.2%, and no KEV listing, exploitation risk is currently low but typical of file-parsing bugs that attackers favor for spear-phishing lures.
Estimated exposure
nichelikely tens of thousands of seats worldwide (specialized scientific desktop application) — No install counts or scan data were provided; the estimate is based on OriginPro's deployment pattern as niche, per-seat scientific graphing and data-analysis software used mainly in academic and industrial research labs.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
OriginLab OriginPro OPJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab OriginPro. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of OPJ files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated data structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29332.