CVE-2025-40827
7.8Siemens · Software Center, Solid Edge SE2025
Siemens Software Center and Solid Edge SE2025 are vulnerable to DLL hijacking, allowing unauthenticated local attackers to execute arbitrary code via a crafted DLL file.
Executive summary
Siemens Software Center and Solid Edge SE2025 contain a DLL hijacking vulnerability that allows local attackers to achieve arbitrary code execution on affected systems.
Vulnerability
The affected software suffers from an uncontrolled search path element (CWE-427), which allows a local attacker to perform DLL hijacking. By placing a malicious DLL in a directory that the application incorrectly searches, an attacker can execute arbitrary code with the privileges of the local user.
Business impact
Successful exploitation of this vulnerability permits unauthorized code execution on the host machine. Given the CVSS score of 7.8, this represents a high-severity risk that could lead to full local system compromise, lateral movement within the network, or the installation of persistent malicious software.
Remediation
Immediate Action: Update Siemens Software Center to version V3.5 or later, and update Solid Edge SE2025 to version V225.0 Update 10 or later as specified in the Siemens security advisory.
Proactive Monitoring: Monitor system logs for unusual process execution patterns or the creation of unexpected DLL files in application directories.
Compensating Controls: Restrict local user permissions to prevent unauthorized file placement in application search paths, and implement application control policies to permit only trusted binaries to execute.
Exploitation status
Public Exploit Available: No — there is no confirmed public exploit in the available data.
Analyst recommendation
This vulnerability presents a significant risk to local system integrity due to the potential for arbitrary code execution. Organizations should prioritize updating all instances of the affected Siemens software to the patched versions provided by the vendor to eliminate the DLL hijacking path. Failure to patch leaves systems susceptible to local privilege escalation or malicious code execution if an attacker can manipulate the application environment.