CVE-2011-4874: Microsys Promotic

High severity, CVSS 7.9. EPSS: 1.5% chance of exploitation in the next 30 days.

Use-after-free vulnerability in MICROSYS PROMOTIC before 8.1.7 allows user-assisted remote attackers to execute arbitrary code or cause a denial of service (data corruption and application crash) via a crafted project (aka .pra) file.

Affected products

  • Microsys Promotic: up to and including 8.1.6; version 8.0.0 only; version 8.0.1 only; version 8.0.2 only; version 8.0.3 only; version 8.0.4 only; …

Published 2012-04-13. Last modified 2026-06-16.