Description
The HCL DFMPro, DFXAnalytics and DFXServer installers are affected by ‘Insecure file permissions Leading to Privilege Escalation’ vulnerability, which enables any logged-in non-administrative user to overwrite or replace the executable file with a malicious binary.
Published: 2026-07-17
Score: 3.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from insecure file permissions on the installers of HCL Software's DFMPro for CATIA, DFXAnalytics, and DFXServer. Because the installed executable files can be written to by any logged‑in non‑administrative user, an attacker can replace the binary with a malicious one. This allows the attacker to run arbitrary code in the context of the application, elevating privileges on the affected system. The weakness is identified as CWE-732, which describes improper access control of a resource.

Affected Systems

The affected products are HCL Software's DFMPro for CATIA, DFXAnalytics, and DFXServer installers. The advisory does not list specific version numbers, so all current releases of these installers should be considered vulnerable.

Risk and Exploitability

The CVSS score of 3.3 indicates low severity, while the EPSS score of less than 1% suggests a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires a logged‑in non‑administrative user who has write permission to the directory containing the installed binary, enabling the user to overwrite or replace the executable.

Generated by OpenCVE AI on July 30, 2026 at 23:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Modify the ownership and permissions of the installed executables so that only administrator accounts can write to the files, setting them to read‑only or otherwise restricted for all other users.
  • Apply any vendor‑issued patches or updates that address insecure file permissions when they become available.
  • Implement file‑integrity monitoring on the binary files to detect and alert on unauthorized changes.

Generated by OpenCVE AI on July 30, 2026 at 23:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 31 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title Insecure File Permissions in HCL Software Installers Enable Privilege Escalation

Wed, 29 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Insecure File Permissions in HCL DFMPro, DFXAnalytics, and DFXServer Installers

Tue, 28 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Hcltech
Hcltech dfmpro For Catia
Hcltech dfxanalytics
Hcltech dfxserver
Vendors & Products Hcltech
Hcltech dfmpro For Catia
Hcltech dfxanalytics
Hcltech dfxserver

Fri, 24 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Insecure File Permissions in HCL DFMPro, DFXAnalytics, and DFXServer Installers

Fri, 17 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 17 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description The HCL DFMPro, DFXAnalytics and DFXServer installers are affected by ‘Insecure file permissions Leading to Privilege Escalation’ vulnerability, which enables any logged-in non-administrative user to overwrite or replace the executable file with a malicious binary.
Weaknesses CWE-732
References
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N'}


Subscriptions

Hcltech Dfmpro For Catia Dfxanalytics Dfxserver
cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-07-17T17:52:43.779Z

Reserved: 2025-09-22T15:00:11.102Z

Link: CVE-2025-59866

cve-icon Vulnrichment

Updated: 2026-07-17T17:52:40.393Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T00:00:06Z

Weaknesses
  • CWE-732

    Incorrect Permission Assignment for Critical Resource