CVE-2025-9450
7.8Dassault Systèmes · SOLIDWORKS eDrawings
A use of uninitialized variable vulnerability in the JT file reading procedure of SOLIDWORKS eDrawings 2025 allows for arbitrary code execution via a specially crafted file.
Executive summary
A critical vulnerability in SOLIDWORKS eDrawings 2025 permits arbitrary code execution, posing a significant risk to workstations that process untrusted JT files.
Vulnerability
The software contains a use of uninitialized variable flaw (CWE-457) within the JT file parsing logic. This vulnerability can be triggered by an unauthenticated attacker if they successfully convince a user to open a malicious JT file.
Business impact
The ability to achieve arbitrary code execution on a workstation allows an attacker to gain full control over the affected system. Given the CVSS score of 7.8, this represents a high-severity risk that could lead to lateral movement within the corporate network, data theft, or the deployment of ransomware.
Remediation
Immediate Action: Organizations should restrict the opening of JT files from untrusted sources until a security update is confirmed and applied. Monitor official Dassault Systèmes security advisories for the release of a corrective patch.
Proactive Monitoring: Security teams should monitor workstation process execution logs for unusual child processes spawned by eDrawings.exe, particularly those involving command shells or network connections.
Compensating Controls: Utilize endpoint detection and response tools to flag or block the execution of SOLIDWORKS eDrawings when processing files originating from external or untrusted email attachments and downloads.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
This vulnerability presents a clear risk to design and engineering environments where external files are frequently imported. Administrators should prioritize the identification of affected SOLIDWORKS Desktop 2025 instances and ensure that users are educated on the risks of opening unsolicited files until the vendor provides a finalized security update.