CVE-2025-9976
An OS Command Injection vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x could allow an attacker to execute arbitrary code on the user's machine.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
- Puntuación base: 9
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.90%
- Percentil entre todas las CVEs puntuadas: 58
- Fecha de la puntuación: 4/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1203Exploitation for Client Executionexecution85 % - Impacto principal
T1059Command and Scripting Interpreterexecution90 %
UI:R indica interacción del usuario (archivo preparado). CWE-78 confirma inyección de comandos. AV:N/PR:L permite ejecución remota con credenciales. Impactos: T1059 por ejecución arbitraria de código; T1068 por C:H/I:H/A:H que sugiere escalada a administrador.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-78
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-9976",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-9976",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2025-10-14T13:15:28.135588Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "3DS.Information-Security@3ds.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 9,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 6,
"exploitabilityScore": 2.3
}
]
},
"affected": [
{
"source": "3DS.Information-Security@3ds.com",
"affectedData": [
{
"vendor": "Dassault Systèmes",
"product": "Station Launcher App in 3DEXPERIENCE platform",
"versions": [
{
"status": "affected",
"version": "Release 3DEXPERIENCE R2022x Golden",
"versionType": "custom",
"lessThanOrEqual": "Release 3DEXPERIENCE R2022x.FP.CFA.2540"
},
{
"status": "affected",
"version": "Release 3DEXPERIENCE R2023x Golden",
"versionType": "custom",
"lessThanOrEqual": "Release 3DEXPERIENCE R2023x.FP.CFA.2532"
},
{
"status": "affected",
"version": "Release 3DEXPERIENCE R2024x Golden",
"versionType": "custom",
"lessThanOrEqual": "Release 3DEXPERIENCE R2024x.FP.CFA.2537"
},
{
"status": "affected",
"version": "Release 3DEXPERIENCE R2025x Golden",
"versionType": "custom",
"lessThanOrEqual": "Release 3DEXPERIENCE R2025x.FP.CFA.2532"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2025-10-13T08:15:41.547",
"references": [
{
"url": "https://www.3ds.com/trust-center/security/security-advisories/cve-2025-9976",
"source": "3DS.Information-Security@3ds.com"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "3DS.Information-Security@3ds.com",
"description": [
{
"lang": "en",
"value": "CWE-78"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An OS Command Injection vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x could allow an attacker to execute arbitrary code on the user's machine."
},
{
"lang": "es",
"value": "Una vulnerabilidad de inyección de comandos del sistema operativo que afecta a la aplicación Station Launcher en la plataforma 3DEXPERIENCE desde la versión 3DEXPERIENCE R2022x hasta la versión 3DEXPERIENCE R2025x podría permitir a un atacante ejecutar código arbitrario en la máquina del usuario."
}
],
"lastModified": "2026-09-26T00:10:00.127",
"sourceIdentifier": "3DS.Information-Security@3ds.com"
}