CVE-2025-33076
8.8IBM · Engineering Systems Design Rhapsody
IBM Engineering Systems Design Rhapsody is vulnerable to a stack-based buffer overflow due to improper bounds checking, which allows a local attacker to execute arbitrary code.
Executive summary
A stack-based buffer overflow in IBM Engineering Systems Design Rhapsody versions 9.0.2, 10.0, and 10.0.1 poses a high risk of arbitrary code execution by local attackers.
Vulnerability
The application suffers from a stack-based buffer overflow (CWE-119) caused by insufficient bounds checking on input. While the CVSS vector indicates network access is possible, the vulnerability requires low privileges, meaning an authenticated local user can trigger the overflow to execute arbitrary code.
Business impact
The ability for a local attacker to execute arbitrary code represents a significant threat to system integrity and confidentiality. Given the CVSS score of 8.8, this vulnerability is classified as High severity, as it could lead to full system compromise, unauthorized data access, or the deployment of persistent malware within the engineering environment.
Remediation
Immediate Action: Upgrade to the provided fixed versions: IBM Engineering Systems Design Rhapsody 9.0.2 iFix004, 10.0 iFix002, or 10.0.1 iFix003.
Proactive Monitoring: Review system and application access logs for unusual command execution patterns or abnormal process behavior originating from standard user accounts.
Compensating Controls: Ensure that the principle of least privilege is strictly enforced to limit the impact of a potential compromise by preventing non-administrative users from accessing sensitive system memory areas.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The severity of this vulnerability necessitates immediate attention to prevent potential system-level exploitation. Organizations should prioritize the deployment of the specified iFix patches across all affected Rhapsody instances to eliminate the buffer overflow risk and ensure the continued security of the engineering environment.