Use After Free Vulnerability in SOLIDWORKS eDrawings by Dassault Systèmes
CVE-2025-6972

7.8HIGH

Key Information:

Vendor
CVE Published:
15 July 2025

What is CVE-2025-6972?

A Use After Free vulnerability exists within the file reading procedure of CATPRODUCT files in the SOLIDWORKS eDrawings application. This flaw allows attackers to execute arbitrary code when opening a specially crafted CATPRODUCT file, potentially compromising systems running SOLIDWORKS Desktop 2025. Organizations should prioritize patching to mitigate potential security risks associated with this vulnerability.

Affected Version(s)

SOLIDWORKS eDrawings Release SOLIDWORKS Desktop 2025 SP0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-6972 : Use After Free Vulnerability in SOLIDWORKS eDrawings by Dassault Systèmes