CVE-2025-9449
7.8Dassault Systèmes · SOLIDWORKS eDrawings
A Use After Free vulnerability in the PAR file reading procedure of SOLIDWORKS eDrawings 2025 allows local attackers to achieve arbitrary code execution via a specially crafted file.
Executive summary
A critical Use After Free vulnerability in SOLIDWORKS eDrawings 2025 exposes users to arbitrary code execution when processing malicious PAR files.
Vulnerability
This is a Use After Free vulnerability (CWE-416) triggered during the PAR file parsing process. The flaw requires user interaction to open a malicious file, but it does not require authentication to trigger.
Business impact
The ability to execute arbitrary code on a workstation can lead to total system compromise, unauthorized access to proprietary engineering data, and potential lateral movement within the corporate network. With a CVSS score of 7.8, this vulnerability represents a high risk, particularly for design and manufacturing environments where intellectual property is a primary target.
Remediation
Immediate Action: Users should restrict the opening of PAR files from untrusted sources and monitor the official Dassault Systèmes Trust Center for the release of a security patch.
Proactive Monitoring: Security teams should monitor workstation endpoint logs for abnormal application crashes or unexpected child processes spawned by the eDrawings application.
Compensating Controls: Deploy endpoint protection solutions capable of detecting malicious file execution and implement strict application control policies to limit the execution of untrusted binaries.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for remote code execution, organizations utilizing SOLIDWORKS eDrawings 2025 must prioritize this issue. Until a vendor-supplied patch is available, technical teams should communicate the risk of opening untrusted PAR files to all relevant personnel and ensure that endpoint security software is fully updated to detect suspicious activity.