CVE-2025-6974

7.8

Dassault Systèmes · SOLIDWORKS eDrawings

A use of uninitialized variable vulnerability in the JT file reading process of SOLIDWORKS eDrawings allows for potential arbitrary code execution via specially crafted files.

Executive summary

A critical use of uninitialized variable vulnerability in SOLIDWORKS eDrawings allows attackers to achieve arbitrary code execution by enticing a user to open a malicious JT file.

Vulnerability

The vulnerability exists within the JT file parsing mechanism, which fails to properly initialize variables before use. An attacker can exploit this flaw by providing a specially crafted JT file that, when opened by an unsuspecting user, triggers memory corruption leading to arbitrary code execution.

Business impact

The potential for arbitrary code execution poses a severe risk to organizational security, as it could lead to full system compromise, unauthorized data exfiltration, or the installation of persistent threats. With a CVSS score of 7.8, this high-severity flaw represents a significant threat to environments where 3D CAD data is frequently shared and opened. The reliance on user interaction via file opening does not diminish the risk, as such vectors are common in targeted phishing or supply chain attacks.

Remediation

Immediate Action: Users should restrict the opening of JT files from untrusted or unverified sources until a security update is applied. Monitor the official Dassault Systèmes trust center for the release of a patched version of SOLIDWORKS eDrawings.

Proactive Monitoring: Security teams should monitor endpoint logs for abnormal process behavior or unexpected crashes in the eDrawings application when processing CAD files.

Compensating Controls: Deploy endpoint detection and response (EDR) solutions to identify and block suspicious file-handling activities or unauthorized child processes spawned by the eDrawings application.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for arbitrary code execution, this vulnerability warrants immediate attention despite the requirement for user interaction. Organizations should prioritize updating their SOLIDWORKS installations as soon as the vendor provides a fix. In the interim, enforce strict policies regarding the handling of third-party JT files to mitigate the primary attack vector.

More Dassault Systèmes CVEs

Sources