You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
cve-2025-7229
About this tag
The tag cve-2025-7229 covers a remote code execution vulnerability disclosed in INVT VT-Designer and HMITool, two engineering and HMI utilities used in industrial and building automation. The flaw, part of a cluster of high-severity CVEs, stems from improper file-parsing logic that can lead to out-of-bounds writes and type-confusion when a user opens a crafted project or VPM file. Successful exploitation allows arbitrary code execution in the context of the application, posing risks to Windows-based engineering stations and operator workstations in ICS environments. Mitigations and coordinated disclosure details are discussed in the tagged content.
INVT’s VT‑Designer and HMITool — two engineering and HMI utilities widely used in industrial and building automation environments — are the subject of a coordinated vulnerability disclosure that assigns multiple high‑severity remote code execution (RCE) flaws to file‑parsing logic in both...