CVE-2025-6971

HIGH

SOLIDWORKS Desktop 2025 - Use After Free

Title source: llm
STIX 2.1

Description

Use After Free vulnerability exists in the CATPRODUCT file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025. This vulnerability could allow an attacker to execute arbitrary code while opening a specially crafted CATPRODUCT file.

References (1)

Core 1

Scores

CVSS v3 7.8
EPSS 0.0016
EPSS Percentile 5.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-416
Status published
Products (1)
Dassault Systèmes/SOLIDWORKS eDrawings Release SOLIDWORKS Desktop 2025 SP0 - Release SOLIDWORKS Desktop 2025 SP2
Published Jul 15, 2025
Tracked Since Feb 18, 2026