CVE-2025-40739
7.8Siemens · Solid Edge SE2025
Siemens Solid Edge SE2025 is susceptible to an out-of-bounds read vulnerability when parsing specially crafted PAR files, potentially allowing for arbitrary code execution.
Executive summary
A critical out-of-bounds read vulnerability in Siemens Solid Edge SE2025 could allow an attacker to execute arbitrary code within the context of the current process via a malicious PAR file.
Vulnerability
This is an out-of-bounds read flaw (CWE-125) triggered by the parsing of malformed PAR files. An attacker can leverage this memory corruption to execute code, provided they can trick a user into opening a specially crafted file.
Business impact
Successful exploitation poses a significant threat to workstation integrity and data confidentiality. Because the vulnerability allows for code execution, an attacker could gain control over the affected system, leading to potential data theft or the deployment of secondary malware. With a CVSS score of 7.8, the risk is high, particularly in engineering environments where users frequently interact with untrusted CAD files.
Remediation
Immediate Action: Update Siemens Solid Edge SE2025 to version V225.0 Update 5 or later to resolve the underlying memory handling error.
Proactive Monitoring: Monitor endpoint security logs for unexpected process crashes or suspicious child processes spawned by the Solid Edge executable.
Compensating Controls: Implement strict email and file transfer filtering to prevent users from opening unsolicited or unverified PAR files from untrusted sources.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Organizations utilizing Siemens Solid Edge SE2025 must prioritize the deployment of the V225.0 Update 5 patch. Given the potential for code execution, delaying this update increases the risk of successful compromise through social engineering or malicious file delivery. Establish a clear patching schedule to ensure all engineering workstations are brought to the secure version immediately.