Description
An OS Command Injection vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x could allow an attacker to execute arbitrary code on the user's machine.
Problem types
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Product status
Release 3DEXPERIENCE R2022x Golden
Release 3DEXPERIENCE R2023x Golden
Release 3DEXPERIENCE R2024x Golden
Release 3DEXPERIENCE R2025x Golden
References
www.3ds.com/...er/security/security-advisories/cve-2025-9976