PT-2025-41467 · Newforma · Newforma Project Center Server

Adam Merrill

+6

·

Published

2025-10-09

·

Updated

2026-01-09

·

CVE-2025-35051

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Newforma Project Center Server (NPCS) (affected versions not specified)
Description Newforma Project Center Server (NPCS) allows a remote, unauthenticated attacker to execute arbitrary code with 'NT AUTHORITYNetworkService' privileges. This is possible because the software accepts serialized .NET data via the /ProjectCenter.rem API endpoint on port 9003/tcp. The vulnerable endpoint is intended to be accessible only on an internal network according to the recommended architecture. The vulnerable parameter is the serialized .NET data sent to the /ProjectCenter.rem endpoint.
Recommendations Restrict network access to Newforma Project Center Server (NPCS).

Fix

RCE

Missing Authentication

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2025-35051

Affected Products

Newforma Project Center Server