CVE-2025-33077

8.8

IBM · Engineering Systems Design Rhapsody

IBM Engineering Systems Design Rhapsody versions 9.0.2, 10.0, and 10.0.1 are vulnerable to a stack-based buffer overflow that allows local users to execute arbitrary code.

Executive summary

A high-severity stack-based buffer overflow in IBM Engineering Systems Design Rhapsody allows local authenticated users to achieve arbitrary code execution.

Vulnerability

This vulnerability is caused by improper bounds checking within the software, resulting in a stack-based buffer overflow. An authenticated local user can exploit this memory corruption flaw to execute arbitrary code on the underlying system.

Business impact

The ability for a local user to execute arbitrary code presents a critical risk to system integrity and confidentiality. Successful exploitation could lead to full system compromise, unauthorized data access, or lateral movement within the network. With a CVSS score of 8.8, this vulnerability is classified as High severity, necessitating prompt remediation to prevent potential privilege escalation or persistence by malicious actors.

Remediation

Immediate Action: Upgrade to the provided iFix versions: 9.0.2 iFix004, 10.0 iFix002, or 10.0.1 iFix003 as specified in the IBM security bulletin.

Proactive Monitoring: Review system and application logs for unusual crashes or signs of unauthorized process execution that may indicate an attempt to trigger the buffer overflow.

Compensating Controls: Restrict access to the application to only authorized users and monitor local user activity, as the exploit requires local access to the system.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the potential for arbitrary code execution, administrators should prioritize the deployment of the specified iFix patches. Ensure that all systems running the affected versions of IBM Engineering Systems Design Rhapsody are updated immediately to eliminate the underlying memory corruption risk.

More IBM CVEs

Sources