Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2025-58777

CVE-2025-58777: Keyence VT Studio RCE Vulnerability

CVE-2025-58777 is a remote code execution flaw in Keyence VT Studio affecting versions 8.53 and prior. Attackers can exploit uninitialized pointers via crafted files to execute arbitrary code on systems.

Published:

CVE-2025-58777 Overview

CVE-2025-58777 is an access of uninitialized pointer vulnerability [CWE-824] affecting Keyence VT Studio versions 8.53 and prior. VT Studio is a configuration and programming environment used with Keyence touch panel displays in industrial control environments. An attacker who convinces a user to open a specially crafted project file can trigger execution of arbitrary code in the context of the running application. The flaw was published to the National Vulnerability Database on 2025-10-02 and coordinated through JPCERT/CC under advisory JVNVU97069449.

Critical Impact

A maliciously crafted VT Studio file can lead to arbitrary code execution on the engineering workstation, providing an entry point into operational technology environments.

Affected Products

  • Keyence VT Studio version 8.53
  • Keyence VT Studio versions prior to 8.53
  • Engineering workstations used to author Keyence VT touch panel projects

Discovery Timeline

  • 2025-10-02 - CVE-2025-58777 published to NVD
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-58777

Vulnerability Analysis

The vulnerability is classified as access of uninitialized pointer [CWE-824]. VT Studio reads structured project files that describe screens, tags, and device configurations for Keyence touch panel hardware. When the application parses a malformed file, a pointer is dereferenced before it has been initialized to a valid memory address. The attacker controls the contents of that uninitialized memory through the crafted file, which redirects program control flow into attacker-supplied data. Successful exploitation yields arbitrary code execution under the privileges of the user running VT Studio. Because engineering workstations frequently hold credentials and network access into industrial control system networks, compromise of this host can be leveraged for lateral movement into the OT environment.

Root Cause

The defect originates in the file parsing logic of VT Studio 8.53 and earlier. The application does not validate that an internal pointer has been assigned a valid object before using it during deserialization of project file structures. Attacker-controlled fields within the file influence the value read from uninitialized memory, allowing manipulation of an indirect function call or data access.

Attack Vector

Exploitation requires local access and user interaction. The attack vector is file-based: the operator must open the malicious VT Studio project file. Delivery typically occurs through phishing, malicious removable media, or shared engineering project repositories. No network exposure of VT Studio itself is required, and no prior privileges on the workstation are needed beyond the ability to run VT Studio. No public proof-of-concept exploit is currently available, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog.

Detection Methods for CVE-2025-58777

Indicators of Compromise

  • Unexpected child processes spawned by the VT Studio executable, such as command shells, scripting hosts, or rundll32.exe.
  • VT Studio project files received from untrusted sources or arriving via email, removable media, or messaging applications.
  • Crash events or Windows Error Reporting entries referencing access violations within the VT Studio process.
  • Outbound network connections originating from the VT Studio process to non-Keyence destinations.

Detection Strategies

  • Monitor process lineage on engineering workstations and alert when VT Studio launches interpreters, LOLBins, or shell processes.
  • Apply behavioral identification rules for file-format parsing exploits, focusing on memory access violations followed by code execution.
  • Inspect file shares and email gateways for VT Studio project file types originating outside the approved engineering workflow.

Monitoring Recommendations

  • Centralize endpoint telemetry from OT engineering hosts into a SIEM or data lake for correlation with IT-side detections.
  • Track installed VT Studio versions across the fleet and alert on any host still running 8.53 or earlier.
  • Review user opening patterns for project files sourced from unusual paths such as Downloads, Temp, or removable drives.

How to Mitigate CVE-2025-58777

Immediate Actions Required

  • Upgrade VT Studio to the fixed version published in the Keyence Vulnerability Report.
  • Restrict VT Studio project files to those originating from trusted, internal engineering repositories.
  • Instruct operators not to open VT Studio files received via email, external media, or unverified sources.
  • Apply application allowlisting on engineering workstations to limit what VT Studio can spawn.

Patch Information

Keyence has released a fixed version of VT Studio addressing CVE-2025-58777. Refer to the vendor advisory at the Keyence Vulnerability Report and the coordinated disclosure at the JVN Security Advisory JVNVU97069449 for download instructions and version details.

Workarounds

  • Segment engineering workstations from general-purpose IT networks and the internet to reduce delivery paths for malicious files.
  • Run VT Studio under a standard user account rather than an administrator account to limit post-exploitation impact.
  • Enforce file integrity checks or digital signing on internal VT Studio project repositories.
  • Disable auto-open behavior for project files and require explicit user verification of file origin.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.