Description
An unauthenticated attacker can trick a local user into executing arbitrary commands by opening a deliberately manipulated project file with an affected engineering tool. These arbitrary commands are executed in the user context.
Problem types
CWE-502 Deserialization of Untrusted Data
Product status
Any version before 3.1.4024.67
Credits
Peter Cheng
ELEX FEIGONG RESEARCH INSTITUTE of Elex CyberSecurity, Inc.
References
certvde.com/en/advisories/VDE-2025-075