Impact
The vulnerability arises from insecure file permissions on the installers of HCL Software's DFMPro for CATIA, DFXAnalytics, and DFXServer. Because the installed executable files can be written to by any logged‑in non‑administrative user, an attacker can replace the binary with a malicious one. This allows the attacker to run arbitrary code in the context of the application, elevating privileges on the affected system. The weakness is identified as CWE-732, which describes improper access control of a resource.
Affected Systems
The affected products are HCL Software's DFMPro for CATIA, DFXAnalytics, and DFXServer installers. The advisory does not list specific version numbers, so all current releases of these installers should be considered vulnerable.
Risk and Exploitability
The CVSS score of 3.3 indicates low severity, while the EPSS score of less than 1% suggests a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires a logged‑in non‑administrative user who has write permission to the directory containing the installed binary, enabling the user to overwrite or replace the executable.
OpenCVE Enrichment