Impact
Solid Edge SE2025 and SE2026 applications contain a use‑after‑free vulnerability that can be triggered while parsing specially crafted DFT files. Exploitation of this flaw allows an attacker to execute arbitrary code within the context of the running application, potentially compromising confidentiality, integrity, and availability of the host system.
Affected Systems
The vulnerability affects Siemens Solid Edge SE2025 versions earlier than V225.0 Update 15 and Solid Edge SE2026 versions earlier than V226.0 Update 7. Users of these older releases are susceptible if they open or process malicious DFT files.
Risk and Exploitability
The CVSS score of 7.3 indicates a high severity level, though no EPSS score is available and the issue is not listed in CISA KEV. The likely attack vector is that an attacker provides a malicious DFT file to a user running Solid Edge, which may be local or remote if the file is transmitted over a network or shared repository. Given the use‑after‑free nature, exploitation requires successful parsing of the file and proper memory handling, so observed exploit activity is expected to be moderate unless the vulnerability is actively leveraged.
OpenCVE Enrichment