Impact
A flaw in the Siemens IAM Client SDK allows an authenticated user to manipulate the library search path used during runtime, enabling the loading of a malicious DLL from an untrusted location. This untrusted search path weakness (CWE‑426) can elevate the privileges of the executing user on the local machine, thereby compromising the confidentiality and integrity of project data within the affected Siemens engineering and simulation products. The vulnerability does not provide remote code execution; it requires local access and an authenticated account.
Affected Systems
All versions of the following Siemens products are vulnerable: COMOS V10.4.5 up to (but not including) V10.4.5.0.2, COMOS V10.6 up to (but not including) V10.6.1, Designcenter NX versions older than V2512.7000, Simcenter 3D older than V2512.7000, Simcenter Femap V2506 until V2506.0003, Simcenter Femap V2512 until V2512.0002, Simcenter Nastran and Simcenter STAR‑CCM+ below V2606, Solid Edge SE2025 before V225.0 Update 13, Solid Edge SE2026 before V226.0 Update 04, Teamcenter Visualization V2412 before V2412.0012, V2506 before V2506.0009, V2512 before V2512.2605, Tecnomatix Plant Simulation V2404 before V2404.0022, V2504 before V2504.0010, and Tecnomatix Process Simulate before V2606.
Risk and Exploitability
With a CVSS base score of 8.5, this local privilege escalation is considered high severity. The EPSS score of less than 1% indicates a very low, but still present, likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is local, requiring an authenticated user that can execute the SDK; once the search path is deceived to load a malicious library, the user’s privileges may be elevated on the host system.
OpenCVE Enrichment