CVE-2025-6971

7.8

Dassault Systèmes · SOLIDWORKS eDrawings

A Use After Free vulnerability in the SOLIDWORKS eDrawings CATPRODUCT file reading procedure allows an attacker to execute arbitrary code via a specially crafted file.

Executive summary

A critical Use After Free vulnerability in SOLIDWORKS eDrawings allows for arbitrary code execution, posing a severe risk to local system integrity.

Vulnerability

This is a Use After Free vulnerability (CWE-416) triggered during the processing of CATPRODUCT files. An attacker can leverage this flaw by inducing a user to open a malicious file, leading to potential arbitrary code execution with the privileges of the victim.

Business impact

The vulnerability carries a CVSS score of 7.8, indicating a high level of severity. Successful exploitation could result in full system compromise, data theft, or the installation of persistent malware within the corporate environment. Because the attack vector requires user interaction, it represents a significant risk for organizations that frequently exchange CAD files from untrusted or external sources.

Remediation

Immediate Action: Review the official Dassault Systèmes security advisory at https://www.3ds.com/trust-center/security/security-advisories/cve-2025-6971 and apply all recommended patches or service packs as soon as they become available.

Proactive Monitoring: Monitor endpoint logs for abnormal crashes or unexpected behavior associated with the eDrawings application process.

Compensating Controls: Implement organizational policies that restrict the opening of CAD files from unverified or external email attachments until the software is updated.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the potential for arbitrary code execution, this vulnerability should be treated as a high priority for engineering and design teams. IT administrators must ensure that all instances of SOLIDWORKS Desktop 2025 are updated to a non-vulnerable version immediately upon vendor release to prevent potential exploitation.

More Dassault Systèmes CVEs

Sources