CVE-2025-6974

HIGH

SOLIDWORKS Desktop 2025 - RCE

Title source: llm
STIX 2.1

Description

Use of Uninitialized Variable vulnerability exists in the JT file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025. This vulnerability could allow an attacker to execute arbitrary code while opening a specially crafted JT file.

Scores

CVSS v3 7.8
EPSS 0.0003
EPSS Percentile 7.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-457
Status published
Products (1)
Dassault Systèmes/SOLIDWORKS eDrawings Release SOLIDWORKS Desktop 2025 SP0 - Release SOLIDWORKS Desktop 2025 SP2
Published Jul 15, 2025
Tracked Since Feb 18, 2026