Home

Description

An OS Command Injection vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x could allow an attacker to execute arbitrary code on the user's machine.

PUBLISHED Reserved 2025-09-04 | Published 2025-10-13 | Updated 2025-10-14 | Assigner 3DS




CRITICAL: 9.0CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

Problem types

CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Product status

Default status
unaffected

Release 3DEXPERIENCE R2022x Golden
affected

Release 3DEXPERIENCE R2023x Golden
affected

Release 3DEXPERIENCE R2024x Golden
affected

Release 3DEXPERIENCE R2025x Golden
affected

References

www.3ds.com/...er/security/security-advisories/cve-2025-9976

cve.org (CVE-2025-9976)

nvd.nist.gov (CVE-2025-9976)

Download JSON