CRITICAL

CVE-2025-9976

2025-10-13 CVSS v3.1
CVSS
9

Description

An OS Command Injection vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x could allow an attacker to execute arbitrary code on the user's machine.

Summary dbcve.org

An OS Command Injection vulnerability exists in the Station Launcher App component of the 3DEXPERIENCE platform spanning versions R2022x through R2025x. Attackers can inject malicious OS commands through unsanitized input in the launcher, leading to arbitrary code execution on the victim's machine.

Mitigation

Apply the vendor-issued patch for affected 3DEXPERIENCE releases (R2022x through R2025x) as soon as possible. Prioritize deployment given the critical severity (CVSS 9) and the availability of public exploitation potential.

Weakness (CWE)

CWE-78 OS Command Injection

EPSS Score

0.9%
Probability of exploitation in next 30 days
58.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE