A vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 12), Solid Edge SE2025 (All versions < V225.0 Update 3). The affected application contains an out of bounds write past the end of an allocated buffer while parsing X_T data or a specially crafted file in X_T format. This could allow an attacker to execute code in the context of the current process.
| Software | From | Fixed in |
|---|---|---|
| siemens / parasolid | 36.1 | 36.1.225 |
| siemens / parasolid | 37.0 | 37.0.173 |
| siemens / solid_edge_se2024 | 224.0 | 224.0.x |
| siemens / solid_edge_se2024 | 224.0-update_0001 | 224.0-update_0001.x |
| siemens / solid_edge_se2024 | 224.0-update_00010 | 224.0-update_00010.x |
| siemens / solid_edge_se2024 | 224.0-update_00011 | 224.0-update_00011.x |
| siemens / solid_edge_se2024 | 224.0-update_0002 | 224.0-update_0002.x |
| siemens / solid_edge_se2024 | 224.0-update_0003 | 224.0-update_0003.x |
| siemens / solid_edge_se2024 | 224.0-update_0004 | 224.0-update_0004.x |
| siemens / solid_edge_se2024 | 224.0-update_0005 | 224.0-update_0005.x |
| siemens / solid_edge_se2024 | 224.0-update_0006 | 224.0-update_0006.x |
| siemens / solid_edge_se2024 | 224.0-update_0007 | 224.0-update_0007.x |
| siemens / solid_edge_se2024 | 224.0-update_0008 | 224.0-update_0008.x |
| siemens / solid_edge_se2024 | 224.0-update_0009 | 224.0-update_0009.x |
| siemens / solid_edge_se2025 | 225.0 | 225.0.x |
| siemens / solid_edge_se2025 | 225.0-update_0001 | 225.0-update_0001.x |
| siemens / solid_edge_se2025 | 225.0-update_0002 | 225.0-update_0002.x |
| siemens / solid_edge_se2025 | 225.0-update_0003 | 225.0-update_0003.x |