CVE-2025-9976
Description
An OS Command Injection vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x could allow an attacker to execute arbitrary code on the user's machine.
Summary dbcve.org
An OS Command Injection vulnerability exists in the Station Launcher App component of the 3DEXPERIENCE platform spanning versions R2022x through R2025x. Attackers can inject malicious OS commands through unsanitized input in the launcher, leading to arbitrary code execution on the victim's machine.
Mitigation
Apply the vendor-issued patch for affected 3DEXPERIENCE releases (R2022x through R2025x) as soon as possible. Prioritize deployment given the critical severity (CVSS 9) and the availability of public exploitation potential.