CVE-2025-6972
7.8Dassault Systèmes · SOLIDWORKS eDrawings
A Use After Free vulnerability in the SOLIDWORKS eDrawings CATPRODUCT file parser allows attackers to execute arbitrary code via a malicious file.
Executive summary
A critical Use After Free vulnerability in SOLIDWORKS eDrawings exposes users to potential arbitrary code execution when opening specially crafted CATPRODUCT files.
Vulnerability
This flaw is a Use After Free (CWE-416) vulnerability triggered during the processing of CATPRODUCT files. An unauthenticated attacker can trigger this condition by providing a victim with a maliciously crafted file that, when opened, results in memory corruption and potential code execution.
Business impact
Successful exploitation of this vulnerability allows an attacker to achieve arbitrary code execution on the host machine. Given the CVSS score of 7.8, this poses a significant risk to organizational endpoints, potentially leading to total system compromise, unauthorized data access, and the lateral movement of threats within the internal network.
Remediation
Immediate Action: Users should immediately update to the latest available version of SOLIDWORKS eDrawings as provided by Dassault Systèmes to incorporate the necessary security patches.
Proactive Monitoring: Security teams should monitor endpoint logs for unusual process execution patterns or crashes originating from the eDrawings application.
Compensating Controls: Restrict the opening of untrusted or externally sourced CATPRODUCT files within the environment and utilize endpoint protection software to scan files for known malicious signatures.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
This vulnerability represents a high risk to workstations running SOLIDWORKS eDrawings. Organizations must prioritize patching affected systems to prevent potential remote code execution scenarios. Until updates are deployed, users should exercise extreme caution when handling CATPRODUCT files from untrusted sources.