CVE-2025-7042
7.8Dassault Systèmes · SOLIDWORKS eDrawings
A Use After Free vulnerability in the IPT file reading procedure of SOLIDWORKS eDrawings may allow for arbitrary code execution via a specially crafted file.
Executive summary
A critical Use After Free vulnerability in Dassault Systèmes SOLIDWORKS eDrawings 2025 allows an unauthenticated attacker to achieve arbitrary code execution by enticing a user to open a malicious IPT file.
Vulnerability
This is a Use After Free vulnerability (CWE-416) triggered during the IPT file parsing process. The flaw requires user interaction to open a malicious file, but it does not require prior authentication to execute.
Business impact
Successful exploitation of this vulnerability could lead to a complete compromise of the affected workstation, enabling an attacker to execute arbitrary code with the privileges of the logged in user. With a CVSS score of 7.8, this represents a high risk to business operations, as it could facilitate unauthorized data exfiltration, the installation of persistent backdoors, or lateral movement within the corporate network.
Remediation
Immediate Action: Update SOLIDWORKS eDrawings to the latest patched version as identified in the official Dassault Systèmes security advisory.
Proactive Monitoring: Monitor endpoint logs for abnormal process execution patterns originating from eDrawings or unexpected file handling errors.
Compensating Controls: Implement strict email filtering and endpoint protection policies to block or scan suspicious IPT files before they reach end user workstations.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for arbitrary code execution and the high CVSS severity, administrators should prioritize patching all instances of SOLIDWORKS eDrawings 2025 within the environment. Users should be cautioned against opening IPT files from untrusted or unexpected sources until the software updates are successfully applied.