Stack-based buffer overflow in Sakura Editor - #VU145346
Published: August 25, 2026
Vulnerability details
The vulnerability allows a local user to execute arbitrary code.
The vulnerability exists due to stack-based buffer overflow in CProcessFactory::StartControlProcess when processing a crafted profile name passed through the command line. A local user can supply an overly long -PROF= argument to execute arbitrary code.
Exploitation requires control over the command-line arguments used to start the application, such as through a modified shortcut or batch script.