PT-2025-41776 · Dassault Systèmes · 3Dexperience

Published

2025-10-13

·

Updated

2025-10-14

·

CVE-2025-9976

CVSS v3.1

9.0

Critical

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions 3DEXPERIENCE versions R2022x through R2025x
Description An OS Command Injection vulnerability exists in the Station Launcher App within the 3DEXPERIENCE platform. This issue could allow an attacker to execute arbitrary code on a user’s machine.
Recommendations Update to a version later than 3DEXPERIENCE R2025x.

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-9976

Affected Products

3Dexperience