CVE-2025-9447

7.8

Dassault Systèmes · SOLIDWORKS eDrawings

An out-of-bounds read vulnerability in the PAR file parsing procedure of SOLIDWORKS eDrawings 2025 may allow for arbitrary code execution via a specially crafted file.

Executive summary

A critical out-of-bounds read vulnerability in SOLIDWORKS eDrawings 2025 could allow an attacker to achieve arbitrary code execution through the processing of malicious PAR files.

Vulnerability

This vulnerability is an out-of-bounds read (CWE-125) occurring within the PAR file reading procedure. It requires user interaction to open a specially crafted file, but does not require prior authentication by the attacker.

Business impact

Successful exploitation of this vulnerability could lead to full system compromise, as the flaw permits arbitrary code execution. Given the CVSS score of 7.8, this represents a high-severity risk that could result in the theft of proprietary design data, unauthorized access to internal systems, or severe operational disruption.

Remediation

Immediate Action: Users should restrict the opening of untrusted PAR files and apply security updates provided by Dassault Systèmes as soon as they become available.

Proactive Monitoring: Monitor endpoint activity for unexpected process execution or abnormal memory usage patterns associated with the eDrawings application.

Compensating Controls: Utilize file integrity monitoring and ensure that endpoint security solutions are configured to scan files for malicious signatures before they are opened by users.

Exploitation status

Public Exploit Available: No (exploit_available: unknown)

Analyst recommendation

Due to the potential for arbitrary code execution, this vulnerability poses a significant risk to the integrity and confidentiality of engineering environments. Organizations utilizing the affected versions of SOLIDWORKS eDrawings should treat this as a high-priority item and ensure that all systems are patched immediately upon the release of a vendor fix.

More Dassault Systèmes CVEs

Sources