highOther

Mitsubishi Electric MELSOFT Update Manager Multiple Vulnerabilities (7-Zip Component)

First seen Jul 5, 2026 · Updated Jul 5, 2026 · CVSS 8.8

icsotmitsubishi-electric7-zippath-traversalbuffer-overflowdenial-of-servicecritical-manufacturingcisa-advisory

Mitsubishi Electric MELSOFT Update Manager SW1DND-UDM-M versions 1.000A through 1.014Q contain four vulnerabilities in its bundled 7-Zip component, including a heap-based buffer overflow, NULL pointer dereference, link following, and path traversal issue. Successful exploitation requires local access and user interaction to decompress a specially crafted archive, and could lead to denial-of-service, data tampering, or arbitrary code execution. No public exploitation has been observed, and the vulnerabilities are not remotely exploitable.

Technical Analysis

The advisory covers four CVEs affecting the 7-Zip component embedded in MELSOFT Update Manager: CVE-2025-53816 (CWE-122 heap-based buffer overflow, CVSSv3 5.0), CVE-2025-53817 (CWE-476 NULL pointer dereference, CVSSv3 5.0), CVE-2025-55188 (CWE-59 link following, CVSSv3 7.9), and CVE-2025-11001 (CWE-22 path traversal enabling arbitrary code execution, CVSSv3 8.8, CVSSv4 9.3 critical). All require a local attacker to convince a user to decompress a maliciously crafted archive file, with no remote exploitability and no known active exploitation reported to CISA. This is a classic ICS engineering-workstation software supply chain risk tied to a vulnerable third-party compression library rather than a network-facing exposure. There is no direct or plausible impact to AI agent systems, LLM tool use, or RAG pipelines, as this affects industrial engineering software on OT workstations with local, user-interaction-dependent attack vectors.

Affected Systems

Mitsubishi Electric MELSOFT Update Manager SW1DND-UDM-M versions >=1.000A and <=1.014Q, used on engineering workstations in Critical Manufacturing sector environments worldwide.

Indicators of Compromise

  • No specific IOCs published; vulnerability relates to malicious archive files decompressed via the affected 7-Zip component (no hashes, IPs, or domains provided in advisory).

Remediation Steps

  1. 1

    Apply vendor fix

    Update MELSOFT Update Manager SW1DND-UDM-M to fixed version 1.015R or later, available via Mitsubishi Electric's download portal.

  2. 2

    Network isolation

    Keep affected PCs within a LAN and block remote logins from untrusted networks, hosts, and users.

  3. 3

    Use firewall/VPN controls

    Restrict remote access to trusted users only through firewall or VPN when internet access is required.

  4. 4

    Restrict physical access

    Limit physical access to PCs running the affected product and their connected networks.

  5. 5

    User awareness

    Train users to avoid clicking links or opening attachments in unsolicited emails, since exploitation requires decompressing a malicious archive.

  6. 6

    Endpoint protection

    Install and maintain anti-virus software on hosts running the affected product.

CVE / Advisory IDs

CVE-2025-53816CVE-2025-53817CVE-2025-55188CVE-2025-11001

Industries Most Exposed

Critical ManufacturingIndustrial Control Systems

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.